Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (39%)
- Domains (22%)
- Web Tools (22%)
- Hosting (11%)
- E-mail (6%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 11 days ago |
|
|
Cloud Services | 12 days ago |
|
|
Cloud Services | 28 days ago |
|
|
Hosting | 1 month ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Yaswanth Sai Palaghat (@yaswanthtweet) reportedThere is a cybersecurity hiring wave happening quietly, and most people have not noticed it. OpenAI is giving IBM, Accenture, CrowdStrike, Cisco, Sophos, and Cloudflare early access to an AI model built to find hacking flaws before criminals do. These companies now need people who can check what the AI finds, decide what is real, and fix it fast. Not people who can hack. People who can check the AI's homework in a system that can actually get robbed. The safest tech job in 2026 might be the one checking whether the AI is lying about a vulnerability. #ainews #openai #cybersecurity
-
Mark (@peyoteheadlight) reportedcrazy how cloudflare warp fixes every isp based issue i have how did i only find out about this a few months ago
-
ً (@tracklim) reportedCLOUDflare… oracle CLOUD INFRASTRUCTURE… guys it’s literally in the names also remember the recent aws outages that brought down like half the internet? guess what aws is. A GLOBAL CLOUD INFRASTRUCTURE PLATFORM 😭😭😭😭
-
Cedric (@stack_panic) reportedYour booking page and your customer list run on one $5 a month @Cloudflare subscription. (Free if you don’t need significant automation) Rented most other places the app server alone starts near $25. Same job, $240 a year back.
-
Carl B (@CarlB_jr) reportedBeing in IT I'm constantly harassed to find use cases and implement AI for almost everything. We've found some use cases and several that just don't make sense. But I always tend to play with things at home to really see what things can do and learn without the guardrails put in place at work. Last night I decided to give they API keys to my network to an AI model and told it "I've got ubiquiti hardware, investigate hardware and software settings. Provide any suggested tweaks or fixes to harden my network and improve performance." It went through and found security holes I thought I'd fixed a long time ago, it found several ways to get better performance, etc.. I did a manual backup and told it to go for it before going to bed. This morning I woke up and found it'd made a total of 92 changes to my network, my NVR, my cameras, apparently finding my CloudFlare API key in a config file and then using that to create a CloudFlare Tunnel, closed off my open ports and killed off my Port Forwarding rules. Redid my firewall changing it from IP based to Zone based. Setting up a new VLAN (for a total of 4 now), moved things around to the new VLAN setup, creating documentation for me, an architectural design, security review, security design, network diagram. Then at the end rotated all of my API keys, uploaded them to Bitwarden (found it's way into that as well through a config file), and then purged the new keys from it's memory. OK, I'm sold for certain tasks. Also a little scared/surprised on how it went through and did so much with other services. That's what I get for telling it to just do everything without any approval from me (because I was going to bed).
-
Dwinity (@dwinity_eco) reported@signalapp @Cloudflare the math was never the weak part. the key directory was. every e2e messenger asks you to trust a server handing out keys, and apple shipped contact key verification in ios 17.2 for exactly that. verification you have to remember to do is verification nobody does.
-
trap broker (@trapbroka) reported🚨 THE MACHINE ECONOMY IS QUIETLY BEING BUILT. AI agents are getting something they never had before: IDENTITY + WALLETS. Cloudflare just announced infrastructure that allows AI agents to have a stable identity and make payments within defined limits. Official Cloudflare headline — “Cloudflare Gives AI Agents an Identity and a Wallet” But that’s only one piece. 🇨🇳 DeepSeek just invested $20.8M in Unitree, the Chinese humanoid robotics company. Unitree is being valued at around $9 BILLION. AI is being connected directly to physical machines. Reuters — DeepSeek invests $20.8M in Unitree And while that happens… 🏦 Wall Street is putting real assets on-chain. DTCC has already processed live production trades using tokenized assets, with its broader tokenization service planned for October 2026. DTCC — Tokenization Becomes a Reality Think about what this actually means. AI gets wallets. Robots get AI brains. Financial assets get tokenized. Machines can increasingly interact with digital services and, eventually, with each other economically. AI + CRYPTO + ROBOTICS = THE MACHINE ECONOMY. Everyone is looking at the next memecoin. Meanwhile, the infrastructure for machines to earn, spend and transact is being built in real time. Maybe the next billion users of crypto won’t be human. Maybe they’ll be machines. 🤖
-
Calvin Ayre (@CalvinAyre) reportedThe highly public compromise of the Coldcard cold wallet has dealt a blow to public perception of self-custody and only time will tell if it’s a fatal wound. Coupled with fears (justified or not) of quantum computing’s threat to digital asset security, convincing the public on the advisability of ‘not your keys, not your coins’ will only get harder. Coldcard’s firmware flaw shrank the seed phrase pool, greatly simplifying the attack process. Maybe we need to adopt more creative methods for ensuring the scope of entropy is as wide as possible, like Cloudflare generating encryption keys from its famous wall of lava lamps. Some have suggested a revival of the old paper wallets, given the complexity of QR codes. But paper can burn, get soaked by floods or sprinkler systems, be misplaced, etc. Bitaddress was great for injecting personalized randomness via your cursor movements, but it had its own security issues. The perfect digital security solution likely doesn’t exist. The best defence would be a multi-pronged approach that splits storage across multiple options. It complicates the process but minimizes fallout from attacks aimed at any one source. Better still, maybe the real throwback tech we need to embrace is Bitcoin. You know, the one Satoshi described as electronic cash that was intended to be used, not hoarded? I sympathize with anyone who took a hit from the Coldcard snafu. But if we go back to treating digital wallets like current accounts rather than our own personal Fort Knox, a compromised wallet won’t be painless but it also won’t be catastrophic to one’s financial wellbeing. Use it, don’t lose it.
-
Artyom Shimanski (@a_shimanski) reported@gitcommit90 @Cloudflare most people just never check what's already included
-
Anon But Not Really (@eggcitedherr) reported@p_e_t_e_r_s_e_n cloudflare is itself a problem they control traffic as they please as one big MITM. they convinced everyone to use their botcheck…
-
etaSpirit (@etaSpirit) reported@gluttnousGoddss Hold your horses, i never said i trust them blindly. I know two things for sure, the engine works and cloudflare never said a thing about them scraping websites. As long as these statement hold l'll consider it a valid option.
-
Officially Retired Owl Dope Capone (@Owl_Dope_Capone) reported@Cloudflare You are the cyber threat. Getting randomly blocked from sites non-stop for the last few weeks. Sometimes a refresh works, sometimes not. Sometimes comment sections load, sometimes not. Constant redirects to international sites. Your company sucks.
-
Nick Launches (@nicklaunches) reportedGoogle shipped an AI report in July. Cloudflare shipped a scoreboard last week. Neither one shows you the number that matters. Inside: > citation rate vs mention rate, and why the gap is the opening > what Cloudflare's agent checklist leaves out > the crawler that reads 1,000 of your pages and sends back nobody > the 4 things I would fix on a site this week 👇
-
Robby Seventeen (@Robby_Seventeen) reported@eastdakota @Cloudflare the brand account can't post at 1am about a bad deploy. that's the whole gap right there.
-
phil may (@PhilcMay) reported@nifal_adam @a_shimanski @Cloudflare Durable objects are cheap still even when you need the paid workers teir for key value backed storage. Acting like getting a $5 bill is bad is jusr cringe lol
-
LeminLimez (@LeminLimez) reported@khcrysalis we have tried cloudflare before and it caused issues with the nameserver, breaking other services. We may try it again
-
🦋 hyeseong.kim (@cometkim) reported@yusukebe Does Cloudflare support it?
-
João Tomé (@emot) reportedWhen people look up, traffic goes down! The biggest Internet traffic (HTTP requests) drops broadly followed the eclipse today. I've seen it before (and wrote about it in 2024). I'll just leave this regional data here... Traffic fell by as much as 80% in Westfjords, Iceland, 66% in Aragon, Spain, 49% in Bragança, Portugal, 32% in New Aquitaine, France, and 32% in Wales, UK. (using Cloudflare Radar data — I didn't resist. Actually saw more interesting stuff and did a dashboard... but not my place to go there at this point). Have a good night y'all.
-
Dom Jedro 💪 (@domjedro) reportedStopping the bad guys with Cloudflare: 118,632 malicious requests blocked or challenged in the last month #cloudflare
-
dukeo (@dukeo) reportedThe SSL monitoring that I built in Downdar just saved weeks of revenue. A few weeks ago, I've added some new security rules in Cloudflare on my main project to limit scrapers. The unintended consequence was that it blocked Let'sEncrypt from accessing the server to renew our SSL certificates. Since there was a delay between the security change and the SSL certificate needing renewal, if we didn't have SSL monitoring, it could have gone unnoticed for weeks showing broken pages to our visitors. Downdar's SSL monitor was built exactly to catch this kind of issues before it impacts your bottom line.
-
brappa (@libosto) reported@nukefags @NEVER_G0ON We just had an outage due to cloudflare
-
Marius du Preez (@mdp_sec) reportedA lot of people have asked how the browser side of my AI bug bounty system works. It is probably the part people struggle with most because giving a model browser access is easy. Giving it browser access that can survive real signup flows, CAPTCHA, anti-bot systems, authenticated testing, multiple accounts, and concurrent hunts is a completely different problem. I currently run 100 persistent headed Chrome profiles on the same server as the rest of the research system. They are not disposable Playwright sessions and they are not clean profiles created for every target. Each one has its own Chrome user directory and keeps its cookies, local storage, history, consent state, challenge cookies, saved sessions, and anything else the browser normally accumulates. That means a profile becomes more useful over time. If it has already passed a Cloudflare challenge, accepted a consent banner, signed into Google, or built normal browsing history, that state is still there when it starts again. Four profiles also have their own Google accounts signed in for targets where normal registration is blocked and social login is the only realistic path. Every profile has a fixed Webshare IP. The pool is currently split into 50 US profiles, 20 UK, 10 Australia, 10 Germany, and 10 Singapore. When a target needs a specific country, the system leases a free profile from that range. If geography does not matter, it selects a free profile from the full pool. The same profile returns through the same IP rather than changing exit every request. That matters because the target is not looking at the IP in isolation. It sees the IP, country, timezone, cookies, account history, challenge state, and browser storage together. Keeping an old session while rotating through a different country every few minutes creates more problems than it solves. Chrome also starts with a timezone that matches the profile's exit country. This is done at process level, so Date and Intl behave natively. I am not patching the timezone in JavaScript after the page loads. I do not assume a proxy is good because the provider sold it as residential. All 100 assignments are checked against the live provider inventory. Traffic is sent through every assigned proxy to confirm the actual exit IP and country with Cloudflare. The IPs are also checked through ip-api, ProxyCheck, and Scamalytics so I can compare geography, proxy flags, hosting flags, blacklist data, and fraud risk. Those services disagree more often than people probably expect. A live Australian exit can be routed correctly while one older database still reports another country. One provider can call an IP residential while another calls it business or hosting. The audit records those disagreements and tracks changes over time. It does not automatically replace an IP because one service returned a bad-looking label. Each browser is fully headed. When a profile starts, it gets its own isolated 1920x1080 virtual display, its own small window manager, and its own noVNC connection. The 100 browsers do not share one desktop, so one profile cannot steal focus, resize another browser, or put a window over another hunt. Most of the time the AI drives Chrome through CDP. Each profile has a known CDP port, so the research phases can attach to the existing tab, navigate, inspect the DOM, fill forms, upload files, execute JavaScript, read console output, extract cookies, and capture screenshots. But because it is headed Chrome, I can open the exact same profile from my dashboard at any time. If a login needs MFA, a consent manager is stuck inside a cross-origin iframe, a CAPTCHA does not solve, or something on the page needs human judgment, the system surfaces the profile that needs attention. I open it through noVNC, complete that step, and close the viewer. The browser itself never moved. The same account, IP, cookies, tab, traffic, and authenticated state remain available to the AI when it continues. Every profile also has NoPECHA installed for reCAPTCHA, hCaptcha, Turnstile, Cloudflare challenges, and Geetest. Running the extension across 100 persistent profiles created its own reliability problem. An extension can be installed but missing its API key, missing its stored settings, disabled in the profile, or waiting for Chrome to download its code. Before a profile starts, the lifecycle manager checks the extension files, settings database, preferences, API configuration, and toolbar state against a known working copy. If anything drifted, it repairs the profile while Chrome is stopped. The automation also knows the solver may be clicking inside a challenge, so it waits for the challenge to clear instead of sending CDP input at the same time and breaking it. Normal browser traffic goes through a separate mitmproxy instance for each profile. The route is Chrome, then the profile's MITM, then its fixed Webshare proxy, then the target. Each browser writes to its own flow file, so traffic from two hunts is never mixed together. This is what makes the browser useful for more than navigating pages. The AI can register an account, perform one normal action, and capture the exact requests the real product generated. That includes OAuth redirects, token refreshes, GraphQL operations, multipart uploads, presigned storage requests, CSRF headers, service-worker traffic, and APIs that were never obvious from static recon. Once a valid request exists, the system decides whether it still needs the browser. Most API testing is faster through curl or a script using the browser's authenticated state. IDOR matrices, parameter tampering, injection, race conditions, and mass assignment do not need a UI click for every payload. If a request depends on rotating browser state, a service worker, SPA middleware, or page context, it can be executed inside the existing tab through CDP instead. There is also a no-MITM mode. Some anti-bot systems fingerprint TLS at the edge. Akamai is a good example. Chrome can look normal in JavaScript, but once mitmproxy terminates TLS, the target sees a different network fingerprint and refuses to validate the browser session. For those targets I switch that profile to a small authentication-forwarding tunnel. Chrome still uses the same fixed Webshare IP, but its TLS passes through without being decrypted. I lose traffic capture for that session, but the target sees native Chrome TLS and the login flow works. This is why CAPTCHA, JavaScript fingerprinting, TLS fingerprinting, and IP reputation cannot all be treated as the same browser problem. Each layer has a different fix. Profiles are leased to an exact platform, target, research cycle, and role. Two agents are never allowed to drive the same profile because tabs share cookies, storage, account state, and the same MITM file. Sharing a browser would create fast progress that nobody could trust. When a profile starts, the lifecycle manager archives its previous live capture, checks the exit configuration, fixes stale ports from crashed processes, clears only Chrome's crash-restore markers, verifies the CAPTCHA extension, starts the display, MITM, Chrome, and runtime support, waits for CDP, then records who owns it. When it stops, Chrome closes but the user directory remains. The profile keeps the state that made it useful. Inactive profiles are also included in an encrypted daily backup because recreating Chrome is easy. Recreating months of browser state and authenticated sessions is not. That is the browser stack. The model gets CDP access, but CDP is only one part of it. The useful system is persistent identity, fixed and measured egress, headed Chrome, isolated displays, CAPTCHA handling, traffic capture, native-TLS fallback, human takeover, ownership, and recovery working together. Without those layers, AI spends half the run fighting the environment and then reports the environment failure as target behavior. And yes this is a massive read #BugBounty #CyberSecurity #TogetherWeHitHarder
-
Hamid Siddiqui (@hamidInventions) reported@wickedguro @markgalkev tbh now not 100% sure if it might be the same reason since you mentioned everyone getting this same time but i strongly feel it would be Cloudflare only, I faced this issue few months back. When i was debugging this I disabled Cloudflare proxy for a while and tested posting the posts that were failing to post on TikTok, and they worked fine. I also used to face similar issue with fal.i/replicate where they would randomly fail to get the R2 image url i passed for image generation. It was fixed as well. The exact steps i took I don't recall, would have to check what settings i did change eventually.
-
Artyom Shimanski (@a_shimanski) reported@occupymars___ @Cloudflare all good, ask away. is this cloudflare access you're setting up, or your own login flow?
-
Edeb (@_Edeb) reported@Majora__Z @p_e_t_e_r_s_e_n Cloudflare’s Sept 15 change is bigger than it looks. They’re flipping the default: AI training crawlers get blocked on any page that shows ads, and multi-purpose bots like Googlebot (which still does both search indexing and training data collection in one) get caught in the same net unless the site owner manually opts out. That means a huge chunk of the web — especially free-tier and new sites on Cloudflare — could suddenly stop letting Google crawl them. Implications in plain terms: Google’s index starts going blind on large parts of the internet. Search results get thinner, older, and more reliant on whatever they already have cached or on AI summaries that never send traffic back. Publishers finally get real leverage. They can protect their content from being vacuumed up to train models that compete with them, without (in theory) fully disappearing from search — but only if they carefully configure the settings. Most won’t. A lot of smaller sites will just let the default ride and vanish from Google. Users will notice it slowly: more “no good results,” more AI answers that feel hollow, more content locked behind logins or paywalls because free crawling no longer makes economic sense. The open web’s old deal is dying. For thirty years the bargain was “crawl everything for free and send traffic back.” That deal is broken. Cloudflare is forcing the next phase: either separate your crawlers cleanly, pay for access, or get locked out. It’s not the end of the internet. It’s the end of the free-for-all version of it.
-
Jason · The Orbital Forge🧬🤖 (@occupymars___) reported@a_shimanski @Cloudflare What I’m trying to add: True second factor: Google Authenticator (TOTP) so remote login is email PIN → then app code, not email alone. stuck on policy , sorry thought ok to ask here
-
Kartik (@Kartik8010) reported@Cloudflare can we please fix the bug where we have persistent volumes for h containers 🫡
-
Dragonfang1911 (@dragonfang1911) reportedMake 3 times, the anti bot algorithm is getting way to out of hand, having to verify through cloudflare which has had known issues.
-
John Doe (@StanleyMasinde_) reportedIf you took time to research, you’ll find Cloudflare horror stories. This company is bad news at scale (or at least it used to be). AWS horror stories are about user fault most of the time. Cloudflare will wake up and decide you’re not paying them enough.
-
Artyom Shimanski (@a_shimanski) reported@XJosephCox @Cloudflare yeah, hard caps would fix half the horror stories