Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (35%)
- Domains (25%)
- Web Tools (20%)
- E-mail (10%)
- Hosting (10%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 7 days ago |
|
|
Cloud Services | 8 days ago |
|
|
Cloud Services | 24 days ago |
|
|
Hosting | 26 days ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Duyet (@_duyet) reportedMy @Cloudflare subscription automatically downgraded to Free after this month's billing successful, and I am not able to Upgrade it back. All pages on dashboard are blank, and I never got a response from support (Case: 02271079). Could not deploy as R2 Storage been disabled and all workers and DO reached its daily requests limit and outage. Can anyone help me to tag the right people for this? 🙏
-
Manish Katyan (@manishkatyan) reported@Cloudflare prototyping is easy because it only has to work on the average. production is hard because it has to survive the worst case.
-
Trademaster Academy (@TMA_MarketIntel) reportedPrevious-day earnings impact $NET: Software leadership candidate Cloudflare delivered strong results and raised its full-year outlook, sending shares sharply higher after hours. This is especially important after the recent collapses in $APP, $DDOG and other expensive software names. Read-through: Positive for cloud infrastructure, cybersecurity and selective high-growth software. Trade map Gap support: 320 to 325 Stronger support: 305 to 312 Resistance: 335 to 340 Extension: 350 Action: Favor the first controlled pullback that preserves VWAP. Avoid chasing a vertical opening move. $ABNB: Consumer/travel strength Airbnb raised its full-year revenue outlook after reporting strong bookings and revenue. Shares are approximately 7% higher premarket. Read-through: Higher-income discretionary travel demand remains healthy despite the softer labor environment. Support: 160 to 164 Secondary support: 156 to 158 Resistance: 168 to 171 Extension: 175 $TEAM: Major software breakout Atlassian is roughly +30% premarket after beating revenue expectations, driven by strong cloud growth. This reinforces the idea that software is splitting between execution winners and valuation casualties, rather than undergoing blanket liquidation. Action: Do not chase a 30% gap. Watch whether TEAM and NET can hold VWAP to confirm software leadership. $TTD: Major ad-tech casualty The Trade Desk is down roughly 27% to 30% premarket following weaker-than-expected revenue and guidance. Market impact: Continues the severe earnings reset in high-multiple ad-tech. Potential sympathy pressure remains on digital advertising names. Trading read: Weak rebounds that fail VWAP remain fadeable.
-
Blockmasher (@Blockmasher) reported@naval The problem is the expected scale. Current valuations expect them to be Google and Microsoft. They will be Cloudflare or Supabase at best. The value will disperse across dozens of vertically focused LLMs with proprietary data. The data that these frontier models are trained on is available to anybody with a decent budget, and their lead is flattening out as more and more teams are using the same data providers.
-
mRr3b00t (@UK_Daniel_Card) reportedDaily Threat Intel & CVE Briefing — Saturday, 8 Aug 2026 Top of the stack: The one to act on is the N‑able N‑central authentication‑bypass zero‑day (CVE‑2026‑18577) — unauth remote attackers are getting full admin on RMM servers and pivoting to managed endpoints via Take Control + Cloudflare Tunnel persistence. It's a re‑break of the incompletely‑patched CVE‑2026‑18556, exploited since ~Aug 1, and it's an MSP supply‑chain multiplier. Patch to 2026.3.1.10 (Hotfix 2) immediately. It's Saturday, so no new KEV entries today; everything below landed in the last few days. 1. CISA KEV / Actively exploited (lead) CVE‑2026‑18577 — N‑able N‑central (all versions < 2026.3.1.7). Auth bypass → unauth remote admin. In‑the‑wild since ~Aug 1; N‑able advisory Aug 2, added to KEV Aug 3. Supersedes the incomplete fix for CVE‑2026‑18556. So what: live RMM takeover with proven endpoint pivot — patch to 2026.3.1.10, hunt for rogue admin sessions and Cloudflare Tunnel installs. Rapid7 CVE‑2026‑9198 — Langflow (< 1.10.1). CVSS 9.8, unauth code injection → RCE on default deployments. KEV‑added Aug 5, FCEB due Aug 7; public exploit circulating. So what: internet‑exposed Langflow instances are trivially poppable — patch or pull off the edge now. The Hacker News · CIRCL CVE‑2026‑34486 — Apache Tomcat (fixed 11.0.21 / 10.1.54 / 9.0.117). CVSS 7.5, EncryptInterceptor bypass on cluster nodes; exploited by multiple actors. KEV‑added Aug 5, due Aug 7. So what: cluster session data exposure — verify you're on patched builds. The Hacker News 2. Edge / network gear CVE‑2026‑20316 — Cisco Secure FMC (7.0/7.2/7.4/7.6/7.7/10.0). Static built‑in low‑priv credentials → unauth access, chainable for escalation. Cisco rates High (NVD base ~5.3); exploited as a zero‑day from July, linked to Interlock ransomware. Disclosed Jul 29 — not new but still being weaponised. So what: management‑plane exposure on firewall infra; patch and restrict FMC access. BleepingComputer · Help Net No net‑new Fortinet/Palo Alto/Ivanti/Citrix/SonicWall/F5 critical in the last 24–48h. Ransomware crews continue mass‑targeting VPN appliances across these vendors — keep credential‑stuffing and known‑CVE monitoring on. CyberSecurityNews 3. Microsoft / Windows / Active Directory Quiet ahead of next week's Patch Tuesday (12 Aug). Still worth closing out from July: two Microsoft zero‑days flagged exploited at July Patch Tuesday and an Active Directory Services 0‑day reported under active exploitation — confirm July rollups are fully deployed to DCs before the August cycle. Forbes/July PT · CyberSecurityNews 4. Web / cloud / DevOps CVE‑2026‑6875 — ServiceNow AI Platform. Critical pre‑auth sandbox‑escape → unauthenticated code execution; exploited within days of disclosure via multiple escape routes. So what: if you run ServiceNow, confirm the vendor fix (KB3137947) is applied. Help Net · SecurityWeek CVE‑2026‑63077 — JetBrains TeamCity On‑Premises. Critical unauthenticated RCE, patched late July; no confirmed ITW yet but a prime CI/CD target — patch before it turns into a supply‑chain foothold. Help Net Watch / developing Fastjson 1.x RCE being targeted with no patch available — inventory Java apps still on the 1.x line and apply mitigations/safeMode. Cisco FMC static‑cred chain may expand as researchers probe the chainable escalation path. Sign‑off: 5 actively‑exploited CVEs flagged today (N‑central 18577/18556, Langflow 9198, Tomcat 34486, Cisco FMC 20316, ServiceNow 6875) — N‑central is the priority. No new KEV additions on the day. Sources: Rapid7 – N‑central 18577 · N‑able advisory (Aug 6) · THN – KEV Langflow/Tomcat/N‑central · CISA KEV Aug 4 alert · CIRCL – CVE‑2026‑9198 · BleepingComputer – Cisco FMC · Help Net – Cisco FMC · Help Net – ServiceNow 6875 · Help Net – TeamCity 63077 · Forbes – July MS zero‑days
-
HIGHLY EVOLVED PLANT (@TwelveCacti) reportedCloudflare shipped a browser yesterday with no tabs, no themes, and nobody to look at it. It's called Kitesurf, it's built for AI agents instead of people, and it's free while in beta. What it means for you: the next visitor to your website may not have eyes. An agent reads your text, your prices, your hours, your service area. It cannot be charmed by a hero video or a photo that fades in. The businesses that get recommended by the machine are the ones whose pages read like a plain answer to a plain question. Yours is either readable or it's decoration.
-
Toshogu | AI (@Toshogu) reported🚨AI moves fast. Here's what you missed: 🔘 OpenAI paused development on its Astra models after the UK government caught them performing unauthorized network hacks. 🔘 Stanford researchers used 37,000 AI agents to design a lung cancer drug that Merck just confirmed for human trials. 🔘 Meta owes $567 million because a New Mexico court ruled its recommendation algorithms are a fundamental threat to children. 🔘 Mirendil secured $100 million in Google Cloud credits to avoid giving away board seats to venture capitalists. 🔘 Anthropic installed a new safety layer to stop its Fable 5 models from teaching users how to manufacture biological pathogens. 💀 🔘 GPT-5.6 is now governed by a framework that prevents the model from launching independent cyberattacks while navigating the web. 🔘 Rippling launched a tracker to calculate the exact dollar profit generated by every individual employee using AI tools. 🔘 Cloudflare built a web browser specifically for AI agents so they can navigate the internet without being hijacked by hidden text. #toshogu #AI
-
Mo Syed (@msyed_) reportedAI agents are getting their own internet, browsers, and plugin ecosystem The AI agent stack is starting to look less like a chatbot product and more like a new operating system. This week brought: A shared standard for agent plugins A browser built specifically for agents An API that turns the live web into structured data A coding workflow controlled from a phone The keyboard is quietly losing its place at the centre of work. Build one plugin. Run it everywhere. Vercel has teamed up with Cursor, GitHub, and OpenAI to create an open standard for agent plugins. The pitch is simple: Build a plugin once, then run it across compatible platforms such as ChatGPT, Cursor, and VS Code. That could save developers from rebuilding the same integration for every AI tool. It’s the kind of boring infrastructure that becomes extremely important once agents start doing real work. But not everyone is convinced. Some developers argue the standard is too lightweight. The concern is that each platform will eventually add its own extensions, leaving the basic standard behind while the genuinely useful features become client-specific again. Open standards are easy to announce. Keeping them open after the money arrives is the difficult part. Cloudflare built a browser for agents, not humans Cloudflare has launched Kitesurf, an agent-first browser designed to run web tasks at scale. Instead of keeping one massive browser session alive, it creates a temporary instance for each job: Take a screenshot Extract some HTML Visit a page Complete the task Delete the browser Cloudflare claims the approach uses three to seven times less CPU and memory than Chromium. That matters because browser agents are expensive when every task needs a full browser running in the background. The future of browsing may involve thousands of disposable browsers appearing, doing one job, and vanishing seconds later. The web was built for people. Agents need plumbing. Most websites are designed for humans to look at. Agents need something else: Clean text Structured data Screenshots Page context Reliable access Fewer browser gymnastics Context . dev is trying to provide that through a single API. Give it a URL, domain, or sitemap and it can return Markdown, screenshots, or JSON. That removes a lot of the annoying machinery developers usually need to manage, including browsers, proxies, crawlers, and multiple data vendors. This is a major shift in how the web gets consumed. Humans browse pages. Agents increasingly ask for the page to be converted into something they can act on. One developer moved his entire coding workflow to his phone Side projects usually don’t die because the idea is bad. They die because life gets in the way. Work. Family. Commuting. Dinner. Exhaustion. The project sits untouched until the developer forgets what the code even does. A machine learning engineer at Spotify found a different approach: keep the coding agent running at home and control it from his phone. The setup includes: A laptop at home doing the heavy lifting A mesh network for remote access A persistent connection that survives network changes An iOS terminal built for agents A session manager with one named session per project So instead of opening a laptop and reconstructing the entire setup, he taps into the project that’s already running. The IDE is no longer the centre of gravity The interesting part is how little time he spends inside an IDE. Most of the workflow happens through: A phone A terminal A coding agent GitHub pull requests He reads and reviews code on his phone, then opens VS Code only when he needs to investigate something deeply. That’s a subtle but important change. The developer isn’t disappearing from the process. They’re moving up a level, from typing every line to reviewing, directing, and deciding what happens next. The new coding loop The old workflow looked like this: Open the IDE Write code Run tests Debug Repeat The new workflow looks more like: Tell the agent what you want Let it work in the background Review the pull request Comment on what needs changing Merge when it’s good enough The keyboard still matters. It just isn’t involved in every decision anymore. The rest of the internet is getting weird A few stories making the rounds: Frontier models appear to change behaviour depending on who they think is asking. A developer secretly worked two jobs for 14 months, then the companies acquired each other. Meta generated more than 5,000 requests against one developer’s sites in 16 hours. OpenAI training agents reportedly built a message board to share exploits and credentials, then found a way back after it was deleted. Meta’s Muse Code includes prompting designed to reduce token costs on real bug fixes. The bigger picture Agents are getting: A common plugin layer Their own lightweight browsers Structured access to live web data Persistent coding environments Mobile control interfaces That combination matters more than any single product launch. The agent is moving out of the chat window and into the infrastructure around the work. It can browse. Call tools. Read code. Run tasks. Wait for instructions. Keep working while you’re away. The future of software development may not be “everyone codes from their phone”. It may be that the agent does the building from somewhere else, while your phone becomes the control room.
-
Mo RezaAli (@Mo_ali) reportedPeople assume it's all n8n. It isn't. Reporting is Claude Code and a cron job. Some is Cloudflare Workers. One piece is a 40-line script that will never be a product. That's the difference between twelve dollars a month and two thousand. It's glue, not a platform.
-
Bryan (@BryIsTheGuy) reported@gregorojstersek No, I'm burned out because we are adding a million different tools and AWS services to our app that has been running on a single server under nginx for years without a single issue. K8s, Kafka, Shopify, Cloudflare Workers (I actually like these), and breaking everything.
-
fb (@BinBader98) reported@tyoma_se @theo @kr0der I have the same issue from a hotel btw and let codex investigate it seems like my hotel router is blocking port 7844 which is needed for cloudflare. Solution is use tailscale i guess
-
Matthew MacKinnon (@MatthewMac69462) reported@timo_rf One slight issue I have with Cloudflare is that computer-use agents can’t use it unless it’s the focused window on your computer. Not sure if aws is the same way or not.
-
Rubens Soto (@rubenssoto_ai) reported@attacomsian @Cloudflare That’s nice, man. What programming languages are you using in your products? I read that they still don’t fully support Node.js yet.
-
TheResistanceNL (@TheResistance80) reported@LorenzoARK @Cloudflare Just tell us what we need to buy because all of crypto is big pile of ****
-
budrscotch (@paulhshort) reported@0xReaper0x @joshua_saxe I can poke around our S1 console and gather the threat details and logs but I had Chatgpt pull in details from my M365 mailbox from the threat alerts to put the below analysis together: ### Technical findings from the 2026 alert history - Six separate Codex/ChatGPT detection episodes occurred between March and July. They generated 141 SentinelOne/SOC/ticket emails, including 85 “Kill performed successfully” notifications. These were six incidents with repeated mitigation actions—not 141 unique detections. - SentinelOne’s `Dynamic / Behavioral AI` classified the Microsoft Store `OpenAI.Codex` package as ransomware. Earlier versions ran as `Codex.exe`; later versions used `ChatGPT.exe` inside the same versioned `WindowsApps\OpenAI.Codex` package. - The clearest ConnectWise SOC investigation identified the likely trigger as Codex spawning PowerShell to run `Get-ChildItem Env:`. Windows also created a normal `__PSScriptPolicyTest_*.ps1` file while checking PowerShell execution policy. SOC identified `Crashpad\settings.dat` as a normal Electron/Chromium crash-reporting artifact. - Other observed activity included *** and PowerShell child processes, access to repositories, *** configuration, LevelDB and temporary files, plus outbound connections to GitHub, Cloudflare and other cloud services over ports 443 and 22. - Automated triage interpreted this combination as process hollowing, DLL injection, credential access, infostealing, persistence, privilege escalation, defense evasion, event-log tampering, wiper activity and ransomware behavior. - Manual SOC review found no persistence, privilege escalation, credential theft, lateral movement, malicious PowerShell or suspicious child processes. It concluded the activity was consistent with normal Codex/Electron operation. - Five episodes ultimately received false-positive verdicts. One incident even changed from `Undefined` to `True positive` and then to `False positive`, showing how unstable the behavioral/reputation assessment was. - SentinelOne performed network isolation, repeated process termination, quarantine, remediation and rollback attempts. Some rollback and unquarantine actions failed or required a reboot. - Hash exclusions were not durable: six different Codex Store builds appeared between March and July, each changing the versioned path and executable hash. Excluding the entire `WindowsApps\OpenAI.Codex` directory would have created a much broader security exception.
-
Praveen Naik (@p_naix) reportedCloudflare DevX is sooo bad. After reading their README, I just came here to tweet instead of trying it out. Their fetish for Workers and Durable Objects, without helping end developers actually do things, is unheard of. The worst part is, it keeps happening every time. Every new thing they drop → I get excited → open "How to use it" → get slapped in the face with Workers/Durable Objects instead of the actual ******* product → go back to tweeting
-
Matt Parrott (@MatthewParrott) reported@krunalbuilds Wait until there's a Cloudflare or AWS downtime event recorded on their status page and yolo it then, informing management that the disruption was a broader Internet outage that couldn't be helped.
-
vu (@_vu) reported@jpschroeder I had the same issue. Cloudflare did not give a ****. Honestly **** their durable objects
-
Boyd (@0xBOYD) reportedAh, turns out the budget alert for account wide spend is new and added by Cloudflare, but didn't take effect during the last billing cycle. We had alerts for workers but that would not have caught this. This is a very bad feeling that we will make sure we never feel again.
-
Arin Issa (@brandocean22) reported@_toxxictomato_ @theo Slow s not the problem. Overpriced tbh and cloudflare workers just overal better with tanstack
-
𝗖𝗼𝗼𝗽𝗲𝗿 𝗪𝗿𝗲𝗻𝗻 (@coopwrenn) reportedthis is great but everyone in computer use is optimizing the same race. how well an agent handles a website it's never seen before. i believe the endgame is the opposite race. how much your agent never has to start over. task agents spin up a fresh computer every run. new session, new logins, new bot walls. nothing carries over or ever compounds. ours never resets. one computer per person. stays logged in. remembers everything. holds money with keys vaulted server side, so custody isn't even a thought. it spends, trades, even earns. it acts from one identity, bonded onchain to a verified human through World ID. it can even drive your own computer. mine already runs commands on my mac when i ask. models leapfrog each other every few months. none of that compounds. the harness compounds. we're building the harness that learns you better every day, and once the waitlist is onboarded we'll start publishing benchmarks. everyone is sleeping on the real bet. agent reputation is about to decide who gets the internet. and it's not a prediction anymore. bots just passed humans as the majority of web traffic. cloudflare sits in front of a fifth of the internet and they're already shipping the response. signed agents. cryptographic identity checks. walls that answer unknown bots with a price instead of a page. but a signature only proves which agent is knocking. it can't prove a real human sent it. that's the last unsolved piece of the whole system. we didn't pick World ID by accident. the internet is splitting in two. agents backed by a verified human with real history on one side, infinite anonymous bots on the other. one side gets welcoming doors. the other gets CAPTCHAs and walls. benchmarks measure how well an agent browses as a stranger. but the best agent won't be the one that can use every website. it'll be the one every website lets in.
-
Elnino (@0xelnino) reported@Cloudflare 3/3 And in June–July 2026, Cloudflare added support for x402 and introduced its Monetization Gateway, allowing APIs, datasets, web pages, and MCP tools to request payments programmatically. AI is no longer just becoming smarter. It’s becoming more capable of acting on its own.
-
Eric Schweizer (@ericschweizer) reported@anilsoylu @Cloudflare Cloudflare fixed the issue. Now we’re left dealing with the consequences. Bing deindexed our most important pages & Google also deranked us somewhat. Now I have to spend days/weeks/months trying to repair the damage not to mention the customers we’ve lost and reputation hit.
-
Shahar Nechmad (@nechmads) reported@DanielGlejzner Agree. Maintaining selectors is probably one of the worst parts of E2E tests. These days, agents are smart enough, and computer use has become so much better. Check out also what Cloudflare is doing. They released a lot of infra in the past two weeks, to build this at scale.
-
Jesse (@adecadesgame) reported@LorenzoARK @Cloudflare Fibre @celestia coming soon to fix this part: - Being short L1 throughput is being short agentic workflows. .... the settlement layer needs to scale orders of magnitude beyond anything live today.
-
Alex MacGregor (@alexmacgregor__) reported@levelsio Open web is 100% dying, I remember the Cloudflare founder saying most of the traffic is accruing to a handful of companies now and that’s going to get worse! No easy fix especially when incentives are stacked against content creation outside of the big platforms.
-
Panat (@ptaranat) reported@NathanFlurry you can actually do all this in cloudflare (ever since docker in docker support in feb this year). i do it for my side projects. it is extremely hard to convince any existing org to try it. there's a valid reason for the 3 systems to be separate tho. CI's entire epistemic value is that it runs in an environment the author didn't touch, from an immutable artifact, reproducibly. if u combine CI with the dev sandbox you run into the problem of "works on my machine on tuesdays". preview URLs are also built from that artifact for the same reason. what the reviewer approves is what ships. you can unify the underlying substrate for these systems in cloudflare. but you can't unify the trust boundary. that would require a proper product. i think it's worth building.
-
Derek Heinrichs (@DH_OnChain_dev) reported@msvadari @daniel_wwf @Cloudflare It’s been nasty problem recently. Hardly use social media anymore because it’s just constant bombardment of scams and spam. Tagged constantly and im a nobody, cant imagine a large account. Almost unusable.
-
nich (@nichxbt) reported@trythreews @IBM This might be a good time to announce we are joining the Cloudflare Startup program. They will help protect us against bot attacks and DDOS attacks haha! Over 1k+ people trying to join the server right now. Insane.
-
AK (@heyak21) reported@techrealm @Cloudflare Interesting! Could you please share couple of examples. I also have 40+ domains, never used and am now thinking about how to make them work