WAF – WAF Release – 2026-07-21

This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Adobe ColdFusion and WordPress, alongside enhanced generic protections against enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) obfuscation techniques. To strengthen overall detection capabilities across emerging threat vectors, new emergency detection rules have also been deployed for Generic Rules – Unauthenticated Remote Code Execution (RCE), Generic Rules – Authentication Bypass (Auth Bypass – 2) and Generic Rules – Information Disclosure.

Key Findings

  • CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.

  • CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.

  • CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.

  • CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

Ruleset Rule ID Legacy Rule ID Description Previous Action New Action Comments
Cloudflare Managed Ruleset 7fbdc9407bdb4a4eae2b3d91215e7d31 N/A SSRF – Restricted Protocol Log Block

This is a new detection.

Cloudflare Managed Ruleset 6ca512d240d848d6a0c7ef42a935ee5d N/A SSRF – Obfuscated Host Log Block

This is a new detection.

Cloudflare Managed Ruleset a3fb0870c38440d8a9a0eba81b0230ac N/A LFI – Path Traversal Log Block

This is a new detection.

Cloudflare Managed Ruleset 452a04be3f73458c863d8dae61349c8b N/A Adobe ColdFusion – File Upload Path Traversal – CVE:CVE-2026-48276 Log Block

This is a new detection.

Cloudflare Managed Ruleset a53a3fb491c64d74908081ee9cb61eac N/A Adobe ColdFusion – Path Traversal – CVE:CVE-2026-48282 Log Block

This is a new detection.

Cloudflare Managed Ruleset d8b63828c2344d919b94d2594ac5e21f N/A XSS — JS Bracket Concat Obfuscation – Body Log Disabled

This is a new detection.

Cloudflare Managed Ruleset 264a83a764be428ca41d516ff31f5559 N/A XSS — JS Bracket Concat Obfuscation – Headers Log Disabled

This is a new detection.

Cloudflare Managed Ruleset 4ba21a60837244029183b782987984fd N/A XSS — JS Bracket Concat Obfuscation – URI Log Block

This is a new detection.

Cloudflare Managed Ruleset 1c060d3a371549219ee290d7ed933fcc N/A WordPress – SQL Injection – CVE:CVE-2026-60137 N/A Block

This was labeled as Generic Rules – SQLi.

Cloudflare Managed Ruleset 7dfb2bd4708d4b88b9911dc0550664b6 N/A WordPress – Remote Code Execution – CVE:CVE-2026-63030 N/A Block

This was labeled as Generic Rules – Unauthenticated RCE.

Cloudflare Free Ruleset db003b39b7774859a8d588ce33697a1a N/A WordPress – SQL Injection – CVE:CVE-2026-60137 N/A Block

This was labeled as Generic Rules – SQLi.

Cloudflare Free Ruleset ebd3f2df15c74ddcbf6220c9b5ec246a N/A WordPress – Remote Code Execution – CVE:CVE-2026-63030 N/A Block

This was labeled as Generic Rules – Unauthenticated RCE.

Cloudflare Managed Ruleset c4ca56c0a6a348299d5a93e663167195 N/A Generic Rules – RCE N/A Block

This is a new detection.

Cloudflare Managed Ruleset 6c4135d4d9d745e4866ad83672952826 N/A Generic Rules – Information Disclosure N/A Block

This is a new detection.

Cloudflare Managed Ruleset 7fe6d6f3df774ae2a0011f20930091a3 N/A Generic Rules – Auth Bypass – 2 N/A Block

This is a new detection.

Cloudflare Managed Ruleset aa21c9b8b97743bfb217748b2049a60c N/A Generic Rules – Command Execution – Body – Beta Disabled

This detection has been removed.

Cloudflare Managed Ruleset e7ee67e824844754b513cdf3836855a4 N/A Generic Rules – Command Execution – Header – Beta Disabled

This detection has been removed.

Cloudflare Managed Ruleset 5f2a6681a2b94442b23816286d060a0d N/A Generic Rules – Command Execution – URI – Beta Disabled

This detection has been removed.

Source: Cloudflare

Share This Update