This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Adobe ColdFusion and WordPress, alongside enhanced generic protections against enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) obfuscation techniques. To strengthen overall detection capabilities across emerging threat vectors, new emergency detection rules have also been deployed for Generic Rules – Unauthenticated Remote Code Execution (RCE), Generic Rules – Authentication Bypass (Auth Bypass – 2) and Generic Rules – Information Disclosure.
Key Findings
-
CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.
-
CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.
-
CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.
-
CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 7fbdc9407bdb4a4eae2b3d91215e7d31 | N/A | SSRF – Restricted Protocol | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | 6ca512d240d848d6a0c7ef42a935ee5d | N/A | SSRF – Obfuscated Host | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | a3fb0870c38440d8a9a0eba81b0230ac | N/A | LFI – Path Traversal | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | 452a04be3f73458c863d8dae61349c8b | N/A | Adobe ColdFusion – File Upload Path Traversal – CVE:CVE-2026-48276 | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | a53a3fb491c64d74908081ee9cb61eac | N/A | Adobe ColdFusion – Path Traversal – CVE:CVE-2026-48282 | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | d8b63828c2344d919b94d2594ac5e21f | N/A | XSS — JS Bracket Concat Obfuscation – Body | Log | Disabled |
This is a new detection. |
| Cloudflare Managed Ruleset | 264a83a764be428ca41d516ff31f5559 | N/A | XSS — JS Bracket Concat Obfuscation – Headers | Log | Disabled |
This is a new detection. |
| Cloudflare Managed Ruleset | 4ba21a60837244029183b782987984fd | N/A | XSS — JS Bracket Concat Obfuscation – URI | Log | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | 1c060d3a371549219ee290d7ed933fcc | N/A | WordPress – SQL Injection – CVE:CVE-2026-60137 | N/A | Block |
This was labeled as Generic Rules – SQLi. |
| Cloudflare Managed Ruleset | 7dfb2bd4708d4b88b9911dc0550664b6 | N/A | WordPress – Remote Code Execution – CVE:CVE-2026-63030 | N/A | Block |
This was labeled as Generic Rules – Unauthenticated RCE. |
| Cloudflare Free Ruleset | db003b39b7774859a8d588ce33697a1a | N/A | WordPress – SQL Injection – CVE:CVE-2026-60137 | N/A | Block |
This was labeled as Generic Rules – SQLi. |
| Cloudflare Free Ruleset | ebd3f2df15c74ddcbf6220c9b5ec246a | N/A | WordPress – Remote Code Execution – CVE:CVE-2026-63030 | N/A | Block |
This was labeled as Generic Rules – Unauthenticated RCE. |
| Cloudflare Managed Ruleset | c4ca56c0a6a348299d5a93e663167195 | N/A | Generic Rules – RCE | N/A | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | 6c4135d4d9d745e4866ad83672952826 | N/A | Generic Rules – Information Disclosure | N/A | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | 7fe6d6f3df774ae2a0011f20930091a3 | N/A | Generic Rules – Auth Bypass – 2 | N/A | Block |
This is a new detection. |
| Cloudflare Managed Ruleset | aa21c9b8b97743bfb217748b2049a60c | N/A | Generic Rules – Command Execution – Body – Beta | Disabled | – |
This detection has been removed. |
| Cloudflare Managed Ruleset | e7ee67e824844754b513cdf3836855a4 | N/A | Generic Rules – Command Execution – Header – Beta | Disabled | – |
This detection has been removed. |
| Cloudflare Managed Ruleset | 5f2a6681a2b94442b23816286d060a0d | N/A | Generic Rules – Command Execution – URI – Beta | Disabled | – |
This detection has been removed. |
Source: Cloudflare


