Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (35%)
- Domains (25%)
- Web Tools (20%)
- E-mail (10%)
- Hosting (10%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 7 days ago |
|
|
Cloud Services | 9 days ago |
|
|
Cloud Services | 24 days ago |
|
|
Hosting | 27 days ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Erdal (@ErdalToprak) reportedNever expose your network, tailscale/headscale only and some selected apps with cloudflare tunnel/zero trust You can avoid 99.99% of issues with that simple trick
-
Shelby 🚬 (@TempahYah) reportedBad user experience, especially when users are being redirected to pages displaying Portuguese. I also think Cloudflare would be a better alternative for link shortening, particularly in terms of speed, security, and overall control.
-
AItoolsNow (@AItoolsNow) reportedA headless browser built specifically for AI agents is a smarter move than another Chromium wrapper. Cloudflare's Kitesurf runs on Workers, skips all the human-facing UI overhead, and is designed around agentic concerns: context windows, token costs, prompt injection risks. Free in beta. Devs get programmatic control over cloud-hosted browser instances without spinning up their own infra. Real limitation: 215k web platform tests passed sounds impressive until you remember the open web is enormous. Complex SPAs and login-walled tools will be the stress test. The interesting open question: does building the browser layer give Cloudflare leverage over how AI agents are authenticated and rate-limited across the web?
-
Toshogu | AI (@Toshogu) reported🚨AI moves fast. Here's what you missed: 🔘 OpenAI paused development on its Astra models after the UK government caught them performing unauthorized network hacks. 🔘 Stanford researchers used 37,000 AI agents to design a lung cancer drug that Merck just confirmed for human trials. 🔘 Meta owes $567 million because a New Mexico court ruled its recommendation algorithms are a fundamental threat to children. 🔘 Mirendil secured $100 million in Google Cloud credits to avoid giving away board seats to venture capitalists. 🔘 Anthropic installed a new safety layer to stop its Fable 5 models from teaching users how to manufacture biological pathogens. 💀 🔘 GPT-5.6 is now governed by a framework that prevents the model from launching independent cyberattacks while navigating the web. 🔘 Rippling launched a tracker to calculate the exact dollar profit generated by every individual employee using AI tools. 🔘 Cloudflare built a web browser specifically for AI agents so they can navigate the internet without being hijacked by hidden text. #toshogu #AI
-
Mo RezaAli (@Mo_ali) reportedPeople assume it's all n8n. It isn't. Reporting is Claude Code and a cron job. Some is Cloudflare Workers. One piece is a 40-line script that will never be a product. That's the difference between twelve dollars a month and two thousand. It's glue, not a platform.
-
Celene is in Seattle! (@toasterlighting) reportedthis does raise the question of "why is cloudflare not registering people with different ips as being different people" but i guess maybe the free plan is bad
-
Ymir (@ymir_ke) reported@johnrush "AI produces good design out of the box" Not yet. It makes good ish design. "Good enough" for many things. It isn't producing anything like vercel's home page purely based on its own inspiration. It can't create graphics like cloudflare has on their website either. Maybe it is a skill issue on my part, but I'm sure it will get there eventually.
-
rusa (@rusabuilds) reported@jedisct1 @InSysOut @Cloudflare a false positive has a cost nobody books. the analyst hour is not on any dashboard, so tuning optimises recall against a budget that is never measured, and the team quietly stops reading the feed. that is the real failure, not the score.
-
mRr3b00t (@UK_Daniel_Card) reportedDaniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026 Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today. 1. CISA KEV / actively exploited (lead) CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised. CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today. CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target. CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today. CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks. 2. Edge / network gear CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate. Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched. 3. Microsoft / Windows / AD Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap. 4. Web / cloud / DevOps CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1. CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep. Watch / developing Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks. Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes. Sources: CISA — Adds Three KEVs (Aug 4) CISA — Adds One KEV (Aug 3) The Hacker News — CISA flags Langflow, Tomcat, N-central Rapid7 — CVE-2026-18577 N-central exploited in the wild N-able — N-central Security Update (Aug 2) The Hacker News — Cisco FMC zero-day actively exploited BleepingComputer — Rails Active Storage RCE (CVE-2026-66066) BleepingComputer — WordPress wp2shell RCE public exploits SecurityWeek — Fortinet/Ivanti critical patches Senserva — CISA KEV additions this week One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.
-
WhiskyBone🌻🍅 (@Whisky_Bone) reported@Cloudflare I'm an angry customer and I'll be angry until you host kiwifarms for DDOS protection
-
Gibran Corbin (@Sendable_me) reported@launch_llama Companies where the agent is consuming the product, not delivering the audience — data APIs, expensive compute, premium endpoints. Property records, court filings, financial data. They're already paying for this problem via rate limits, Cloudflare rules, and engineer hours spent making traffic stop. The anti-ICP matters just as much: if agents are how customers find you, don't price anything. Charging at that door costs more than it collects. Buyer's usually a CTO or platform lead at a company small enough that one person decides.
-
Jornalaw online (@maurodemarchi) reportedStopping the bad guys with Cloudflare: 189,076 malicious requests blocked or challenged in the last month #cloudflare
-
dax (@thdxr) reported@arnvbnsl it's end to end encrypted which i haven't found a tunnel service that does this but it ideally will run on cloudflare once they let us into the tcp worker private beta
-
Alex MacGregor (@alexmacgregor__) reported@levelsio Open web is 100% dying, I remember the Cloudflare founder saying most of the traffic is accruing to a handful of companies now and that’s going to get worse! No easy fix especially when incentives are stacked against content creation outside of the big platforms.
-
Kazani (@kazani351) reported5/ The signal most people missed: 47% of all agentic transactions on Base now run through @virtuals_io. Add the x402 wave around Base, Cloudflare, @youdotcom, @browser_use x Coinbase, all letting AI agents pay per request in USDC. Agents are Base's next users.
-
EMCD Coinhold Wallet (@coinhold_wallet) reported@CoinDesk @Cloudflare Per-call billing fits agents well, but the wallet still needs limits that survive a bad prompt or compromised service
-
Zacky vicent (@VicentZacky) reportedTHE “SAASPOCALYPSE” IS HERE — AND WALL STREET IS GETTING ITS TEETH KICKED IN Software stocks just delivered a brutal reminder: AI isn’t simply changing software. It is forcing Wall Street to question what software is actually worth. The carnage started with Airtable. Once valued at nearly $12 billion in 2021, the cloud-software darling agreed to be acquired for less than $1.3 billion — roughly 90% below its peak valuation. That is not a correction. That is a ******* valuation massacre. Then came the earnings bloodbath. HubSpot and Datadog were hammered. Datadog plunged 19%, its worst single-day decline since going public in 2019. Its largest AI customer — widely believed by analysts to be OpenAI — reportedly reduced usage beginning in June. The message to investors was ******* clear: If AI companies can build, monitor, automate, and operate more of their own software internally, why should they keep paying massive recurring fees to traditional SaaS vendors? That is the question terrifying the entire sector. And it gets uglier. Software stocks collapsed 24% in Q1, their worst quarterly performance since 2008. Venture-backed SaaS companies are now trapped between two worlds: They raised enormous amounts of capital at absurd pre-AI valuations — and now they have to prove those valuations weren't bullshit. There hasn't been a significant SaaS IPO in 2026 so far. Meanwhile, 86% of the value of private deals in the first half of 2026 went to AI companies, according to PitchBook. Capital isn't disappearing. It is ******* moving. And Wall Street is following it. But then came the plot twist. Atlassian jumped 35% in one day — its best session since its 2015 IPO. Twilio surged more than 20%. Cloudflare gained 5.6%. Suddenly, the “software is dead” narrative looked a little ******* premature. Atlassian delivered its strongest quarterly profit since 2021, reminding investors that AI doesn't automatically destroy every software business. Sometimes it does the opposite. AI can become a weapon for software companies that adapt fast enough. Atlassian had already cut 10% of its workforce — roughly 1,600 jobs — five months earlier, explicitly to fund further investments in AI and enterprise sales while strengthening its financial profile. That is the new battlefield. Cut costs. Deploy AI. Increase productivity. Defend margins. Prove the customer still needs you. Because the real threat isn't AI itself. The real threat is becoming irrelevant. Salesforce knows it. The company has lost more than 40% of its value since the end of 2024, despite continued revenue growth and consistent margins. Marc Benioff can tell investors that Salesforce's software isn't going anywhere. But Wall Street isn't paying for promises anymore. It wants evidence. And that's why companies like OpenAI Codex and Anthropic's Claude Code are causing such ******* anxiety. If AI agents can increasingly build software that once required expensive teams, then the economic moat around traditional SaaS starts getting attacked from the inside. But here's the part Wall Street may have underestimated: Software isn't necessarily dying. The business model is being ******* rewritten. The winners won't simply be the companies selling software. They will be the companies that use AI to make their software 10x more useful, cheaper to operate, harder to replace, and deeply embedded into enterprise workflows. That explains the violent market swings. Investors are no longer asking: “Is this a great software company?” They're asking: “Will this company still matter when AI agents become exponentially more capable?” That is a much more ******* brutal question. And the market is repricing companies accordingly.
-
Ivan Bermejo (@Ibermejocatalan) reportedCloudflare and Coinbase launched the x402 Foundation. Built on HTTP 402, the status code the web reserved for payments and never used. Now AI agents on Cloudflare Workers can pay for API access in USDC on Base. No card rails, no billing dashboard. The agent hits the endpoint, gets a 402 response with a price, signs a stablecoin tx, and the content unlocks. AWS CloudFront already adopted it too. This is plumbing. The kind that makes agent-to-agent commerce default infrastructure, not a demo.
-
Zubiqo (@zubiqo) reportedUPDATE: 🚨 N-able $NABL issues Hotfix 2 for N-central as attackers breach managed systems. Threat actors exploited CVE-2026-18577 to gain administrative access to N-central servers starting July 31, 2026. Attackers leveraged the Take Control feature to access endpoints and registered Cloudflare Tunnels for persistent access. The flaw stems from an incomplete patch for CVE-2026-18556 and is flagged by CISA as actively exploited. N-able urges on-premise administrators to update to version 2026.3.1.10 immediately even if Hotfix 1 was installed. "This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix." — N-able When an RMM tool gets breached, revoking server access does nothing after attackers plant backdoors across downstream endpoints.
-
Morgan (@morganlinton) reported@jpschroeder Doh, really sorry to hear, and weird there’s no way to set spending limits in CloudFlare, feels like that should be standard for hosting service right?
-
Debbie O'Brien (@debs_obrien) reportedI still don’t understand @Cloudflare (sorry) but used it twice over the last week for backend services and I have to say the agent experience was amazing cause I still don’t understood Cloudflare but I managed to migrate my Azure service which I didn’t build and was not working anymore and is now using Cloudflare. My playwright demo app is now loading movies but it seems login is not fully working since I deployed. Damn it worked on my machine 🤪. Will fix later. But all this was done over a few hours which is pretty incredible. Thanks @cursor_ai and Grok. Have to say I love how I just typed in the word Cloudflare in the prompt and it suggested adding the Cloudflare plugin and took it from there. That’s great product UX.
-
Fraser (@iamfra5er) reportedTHIS GUY WANTED A PLACE TO STORE HIS PASSPORT WITHOUT DROPBOX READING IT so he built an encrypted vault app for himself in a weekend and it's now doing $5k/mo zero startup cost. 85% margins. no ads. just SEO written by an AI agent trained on his emails the agent finds trending topics on reddit every single day, writes an article, translates it, posts it google indexes it in days. 500-600 daily visitors. 4% convert to app store downloads. all running on free cloudflare then ASO does the rest — he translated the app into 36 languages and ranks #1 for "duress vault" in the US app store 80 downloads a day. 9% conversion to paid. completely autonomous most founders obsess over their first 10 customers but this guy got banned from every reddit community and said whatever, I'll just let the robot handle distribution he's an ex-google security engineer who raised hundreds of millions for his last startup so he knows what terrible UX looks like in security apps every competitor either has bulletproof security with unusable UI or easy UI with trash security he just combined both and called it done doesn't even spend time on this app. works on 4 projects at once. lets coding agents build while he plans the MVP is identical to the final product because he built exactly what he wanted for himself no pivot. no customer discovery calls. just "I need this, maybe 10 other people do too" now he's testing tiktok and youtube not even for this app but just to learn distribution for the next one
-
dweewq (@eweqss1431) reportedAgencies charge $8,000 to $12,000 for a marketing site, three weeks of calls, two rounds of revisions, one invoice that makes you sit down. Claude Code builds the same site in an afternoon, but most people still get template output because they type "make it beautiful" and pray. Claude defaults to safe every time: Inter font, purple gradients, three feature cards. The ten thousand dollar look comes from constraints, not vibes. The fix starts before a single line of design gets written. Load actual design rules into Claude Code as skills, so it checks a ruleset before every decision instead of guessing what "premium" means. Then screenshots beat adjectives completely. Three reference sites from your niche, paired with an explicit instruction not to copy the layout, give the model an actual quality bar to hit instead of a vague adjective to interpret. The build itself is one prompt with five blocks: who the audience is, the single action every page should push toward, the references to match, the tech stack, and a banned list of every cliché you don't want showing up. First working version lands in under ten minutes, about seventy percent there, which is exactly the point, nobody ships version one. The part that actually earns the price tag is the polish pass agencies bill forty percent of the project for: typography, spacing, and motion, run as three separate messages instead of one, because asking for all three at once gets one dimension fixed well and two fixed badly. A mobile check at 375px catches what breaks, since most traffic is a phone regardless of what the desktop preview looks like. Shipping costs nothing after that. Push to GitHub, connect Cloudflare Pages, deploy. The agency was always selling three weeks of process. The process was always one afternoon.
-
AK (@heyak21) reported@techrealm @Cloudflare Interesting! Could you please share couple of examples. I also have 40+ domains, never used and am now thinking about how to make them work
-
amey (@samsararunup) reportedtook this to heart i think i have a rough setup down w/ htmx, hono & cloudflare workers/d1 need quick to ship + low boilerplate let's see, i'm giving up on self hosting on VPS legit so CF for all
-
Matthew MacKinnon (@MatthewMac69462) reported@timo_rf One slight issue I have with Cloudflare is that computer-use agents can’t use it unless it’s the focused window on your computer. Not sure if aws is the same way or not.
-
Jeremy (@Jeremybtc) reportedCloudflare built a browser that no human can use Kitesurf renders pages for AI agents only It has no tabs or themes and there's no use for extensions or perfect rendering It runs 3 to 7x lighter on CPU and memory than Chromium It also runs 1.7 to 1.8x slower A bad product for one human user and a great one for ten thousand agents Cloudflare built it in 12 weeks They're not building for the future of people browsing more, they're building so machines can browse more
-
David_Crayford 🇬🇧 (@David_Crayford) reported@benjitaylor 4. Self hosting. Bluesky has its own servers and does not go down when Cloudflare etc go down.
-
Vlad | AI Build Lab (@VladBuildsAI) reported@winsontang This is a good example of why I like measuring AI workflows at the boundary, not at the model output. The source shows the visible part: "Winson Tang · 3 год Discover insights like never before with Cloudflare Radar Researcher". The useful next question is what has to be true around it for the result to survive real work. I would check 5 things: input quality, human review minutes, retry behavior, permission boundaries and recovery after the handoff from research to execution. If those are not measured, the demo can look like automation while the hidden cost sits in cleanup. The metric I would want is retry rate after the first failure. That tells you whether the workflow is reducing total work or just producing more artifacts that somebody else has to validate.
-
Pils10 (@PilsZehn) reported@linkrobinsllc @Samaytwt Agreed. Had some good experiences with Namecheap, their support is super fast and helpful, even if I dislike their "surcharges". Cloudflare is great, but I hate them limiting new domains to 200 rather than 1.000 DNS records. Hostinger is ok-ish, but I personally use Netcup.