1. Home
  2. ❯
  3. Companies
  4. ❯
  5. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 35% Cloud Services (35%)
  • 25% Domains (25%)
  • 20% Web Tools (20%)
  • 10% E-mail (10%)
  • 10% Hosting (10%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 8 days ago
Los Angeles Cloud Services 9 days ago
Paris Cloud Services 25 days ago
New York City Hosting 27 days ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • martinmalindacz
    Martin (@martinmalindacz) reported

    @levelsio the cloudflare monetization gateway could be the answer here if a social media network can actually ensure authentic content then crawlers would pay extra for it

  • jdellamora
    Joe Della Mora (@jdellamora) reported

    @screamingfrog @Cloudflare From ranking to recommended is the right frame. The part that lands hardest locally: there is no page two. Ten positions and a next button collapse into two or three names and a phone number. Position four is not further down the list, it is simply absent.

  • HatsuneMiku119
    Hatsune Miku+war crimes (@HatsuneMiku119) reported

    @PINKUSMONKEY @_itszright How does cloudflare tell you its down do you think...

  • RealChrisCotts
    Chris was Right About Everything πŸ‡ΊπŸ‡Έ (@RealChrisCotts) reported

    @BrianRoemmele Very cautious about anything coming from Cloudflare. Very. They are never on the level.

  • cozybearlog
    μ½”μ§€λ² μ–΄ 🐻 CozyBear (@cozybearlog) reported

    Cloudflare put a browser inside Workers this week. Kitesurf is an agent-first browser that runs server-side, plus WebMCP which gives every website an MCP interface. The part that matters: the browser stopped being a client-side thing and became server infrastructure. If agents get their own browser primitives in the cloud, then every site needs to be agent-ready the same way it's mobile-ready today. That flips a lot of assumptions. Rendering, auth, rate limiting, bot detection, all built for human browsers. The agent economy won't run on APIs, it'll run on browsers that never sleep. We're about to find out which sites survive a headless user that never blinks.

  • firasbuilds
    Firas (@firasbuilds) reported

    Day 5 of building my startup in public. Spent most of today deep in infrastructure. Moved Raccolta from Vercel to Cloudflare, broke a few things along the way, fixed a nasty 404 issue, and ended up making the whole app noticeably faster. Also cleaned up a bunch of small things that had been bothering me for days. No huge feature launch today. Just a lot of fixing, learning, and product improvement. Tomorrow I will hopefully focus more on marketing. :-)

  • AdevAarons
    AdevAarons (@AdevAarons) reported

    Cloudflare just launched AI visibility reporting (AEO). Early access is open. When a company that much of the internet runs through starts measuring "does AI recommend this business," it stops being niche. The category just now got validated. The funny part: Cloudflare made it easy (often default) to block AI's crawlers, and their tool now reports exactly that, the 403s. That's the #1 thing my free audit keeps catching. 100 of 123 businesses I tested were blocking AI without knowing. They're about to show a lot more people they're one of them. Their dashboard shows the wound. My audit shows the whole chain and what to fix, on any site. Glad they built it.

  • UK_Daniel_Card
    mRr3b00t (@UK_Daniel_Card) reported

    Daniel's Daily Threat Intel & CVE Briefing β€” Fri 7 Aug 2026 Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch β€” and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today. 1. CISA KEV / actively exploited (lead) CVE-2026-18577 β€” N-able N-central, all versions ≀ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass β†’ full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised. CVE-2026-18556 β€” N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today. CVE-2026-9198 β€” Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection β†’ RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target. CVE-2026-34486 β€” Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today. CVE-2026-63077 β€” JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks. 2. Edge / network gear CVE-2026-20316 β€” Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account β†’ unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager β€” patch and rotate. Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle β€” no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched. 3. Microsoft / Windows / AD Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 β€” July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap. 4. Web / cloud / DevOps CVE-2026-66066 β€” Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read β†’ potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips β‰₯ 8.13, ruby-vips β‰₯ 2.2.1. CVE-2026-63030 + CVE-2026-60137 β€” WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited β€” worth a scan sweep. Watch / developing Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week β€” details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) β€” watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks. Sign-off: 7 items flagged actively exploited today (N-central Γ—2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes. Sources: CISA β€” Adds Three KEVs (Aug 4) CISA β€” Adds One KEV (Aug 3) The Hacker News β€” CISA flags Langflow, Tomcat, N-central Rapid7 β€” CVE-2026-18577 N-central exploited in the wild N-able β€” N-central Security Update (Aug 2) The Hacker News β€” Cisco FMC zero-day actively exploited BleepingComputer β€” Rails Active Storage RCE (CVE-2026-66066) BleepingComputer β€” WordPress wp2shell RCE public exploits SecurityWeek β€” Fortinet/Ivanti critical patches Senserva β€” CISA KEV additions this week One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly β€” the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.

  • 0xBOYD
    Boyd (@0xBOYD) reported

    @zero_to_seed @luanguyen Stacked instances of a Cloudflare alert edge case, mistakes on our part, and really bad luck on timing. The alert existed but was set mid-cycle (by Cloudflare) and so didn’t take effect until this new billing cycle. The older alert we did have was scoped to workers only and wouldn’t have caught the Durable Object reads. Lastly we happened to hit the bug in our code at the exact start of a billing cycle so it went undetected about as long as theoretically possible. A whole billing cycle before we saw the invoice hit.

  • Sendable_me
    Gibran Corbin (@Sendable_me) reported

    @launch_llama Companies where the agent is consuming the product, not delivering the audience β€” data APIs, expensive compute, premium endpoints. Property records, court filings, financial data. They're already paying for this problem via rate limits, Cloudflare rules, and engineer hours spent making traffic stop. The anti-ICP matters just as much: if agents are how customers find you, don't price anything. Charging at that door costs more than it collects. Buyer's usually a CTO or platform lead at a company small enough that one person decides.

  • 0xelnino
    Elnino (@0xelnino) reported

    @Cloudflare 2/3 Cloudflare is a clear example of this shift. In April 2026, Cloudflare officially expanded its Agent Cloud to support building and running millions of autonomous, long-running agents. It now provides agent runtimes, browsers, sandboxes, MCP, scheduling, identity, and payments

  • trucku_kun
    Trucku-Kun πŸ“€ (@trucku_kun) reported

    @IntCyberDigest Cloudflare sucks , if you use a privacy focused browser cloudflare will loop "verifying you are a human" ****

  • kiruwaaaaaa
    kiruwaaaa (@kiruwaaaaaa) reported

    Base just admitted by quietly killing its own social app... @base spent 2025 building a consumer social network on top of the chain. In July 2026, that got walked back entirely - the app handed off, and the entire chain repointed at three things: trading, payments, and AI agents. > 92.8% of all AI agent payments on the internet right now settle on Base > 99.8% of those payments run in USDC through x402, the protocol Coinbase built with Cloudflare > Base alone has processed over $19 trillion in stablecoin volume this year - more than most G20 economies move annually This isn't a pivot. It's an admission that agents, not people, are about to be the largest customer base ever handed to Coinbase in one product cycle. Stripe is chasing this with MPP. UnionPay has APOP. OKX shipped APP. Four protocols launched in twelve months because everyone can see where the money is going - software paying software, instantly, without a human clicking approve. Base didnt lose the social experiment. It just noticed the actual customer walking through the door wasn't a person at all.

  • 723Magnus
    -- (@723Magnus) reported

    @Saas_addy @AKirtesh @Namecheap Not when you need support it's not. Cloudflare runs a full dns scan before you set to name servers & builds the dns zone file for you. Add domain, verify in email inbox, Turn off orange clouds and change name servers at the registrar. DNS zone changes propagation auto ttl 2 min

  • arjunaditya_
    Arjun Aditya (@arjunaditya_) reported

    @shydev69 I’ve been using cloudflare from almost 4 years but their ui never got on my muscle memory except their dns Now as im handling a lot of websites and traffic Its the best thing possible as i ended up missing some orders because of some downtime

  • Rat_Bag113
    Jimmy Pringles (@Rat_Bag113) reported

    @itslivny Mate do you wanna fix your Cloudflare or something.

  • Jeremybtc
    Jeremy (@Jeremybtc) reported

    Cloudflare just built a broswer that no human can use It's called Kitesurft and it renders pages for AI agents only The browser has no tabs or themes and there's no use for extensions or perfect rendering Running 3 to 7x lighter on CPU and memory than Chromium It also runs 1.7 to 1.8x slower Which makes it a bad product for one human user and a great one for ten thousand agents It was only built in 12 weeks by Cloudflare They're not building for the future of people browsing more, they're building so machines can

  • DaveyHert
    David HerbertπŸ‘¨πŸ½β€πŸ’»πŸš€ (@DaveyHert) reported

    Before my upcoming product lunch, this is for Starlink users on my TL who, like me, hate being restricted to just the Starlink mobile app. I built an open-source Starlink desktop app for macOS, Windows and browsers to monitor the performance and health of your Starlink. Backstory: I've been a Starlink user for over 3 years now, and I've greatly enjoyed having a reliable network, especially since I'm in an area with terrible internet. But as someone who spends most of my time on my MacBook, I've always had to reach for my phone whenever I want to see what's going on with my Starlink, and it bites more when my phone is in a different room. So, about 2 weeks ago, I decided to just build myself a native desktop app that does most of what the mobile app does, plus some extra features I'd always wanted. I've spent the last 2 weeks building and iterating on it to the point where I use it daily. It's been such a wonderful experience that I think it's selfish of me to keep it to myself. I know many Starlink users and community members would love it as much as I do, so I decided to open-source it. So what do you get from Dishylink? Live status β€” throughput, latency, obstruction and hardware health. Dish alignment β€” target rotation and tilt, with the exact nudge in degrees when the dish is off. Speed test β€” download, upload and latency through Starlink to Cloudflare. Satellite tracking and obstruction map β€” 3D satellite constellation overhead, and a time-lapse of what's blocking your view of the sky + which satellite your dish is connected to. Network & Nodes β€” see which client devices are connected to your network and their data usage activity. Data usage β€” every byte through the dish, split by download and upload, with per-client device granular data usage. Power usage β€” real-time draw plus historical energy totals so you can get an idea of what your dish consumes daily, weekly or monthly. Latency analytics β€” whether the lag is Starlink or your own router. Alerts and event log β€” raised when the dish or router stops answering, overheats or hits weather, and cleared once it passes. Controls β€” snow melt, sleep schedule, update window and reboots on supported firmware. Platforms β€” macOS, Windows, and Browser extension alternatives for Chrome, Edge, and Firefox. Privacy: no account, no backend, no analytics. Dishylink reads your hardware over your own network and keeps what it records in your system. Nothing is collected by me, or any third-party service (there's none), and the source code is available to review. I know I could make a decent amount by adding a paywall, since I think it's actually worth every buck, as you'd come to see. But I won't be doing that; my only joy would be seeing it serve the community and probably grow into more than what it is right now. Download links are attached below.πŸ‘‡πŸ½

  • dlxeva
    dlxeva (@dlxeva) reported

    Stopping the bad guys with Cloudflare: 4,960 malicious requests blocked or challenged in the last month #cloudflare

  • cozybearlog
    μ½”μ§€λ² μ–΄ 🐻 CozyBear (@cozybearlog) reported

    Cloudflare open-sourced an OS for companies: employees ask an AI for a work app and get it built on the spot. 4,000 internal apps in 30 days. The prediction here is not that SaaS dies. It is that SaaS degrades from finished product to component. The record keeping, payments, contracts stay. The screens around them get generated per person. That matches what I see in my own tools. The part users stop opening is never the data, it is the fixed dashboard. Once an agent can render the view they need on demand, the managed UI stops being the product. What becomes scarce is not software. It is the record, the permission, the audit trail. Whoever holds the layer between agents and the truth of the company owns the next decade.

  • aryuminstrel
    Aryuemaan Chowdhury (@aryuminstrel) reported

    Stopping the bad guys with Cloudflare 1,314 malicious requests blocked and challenged in the last month #cloudflare

  • jiahanjimliu
    Jim Liu (@jiahanjimliu) reported

    Neoclouds, $IREN: The Inference Market OpenRouter is 2% of global LLM token consumption (1) but 10% of Open Source tokens that's not on-prem aka available to AI Platforms / Neoclouds. Global LLM token consumption includes OpenAI/Anthropic and is massively inflated by free tokens. Let's take a full look of the inference market. Closed Source Although OpenAI holds ~24.4% of the token market vs Anthropic's 15.6%, Anthropic has a much higher revenue share of 40% compared to OpenAI's 27%. On aggregate, Anthropic API is more expensive than OpenAI and OpenAI has moved onto competing with cheaper Open Source models with ChatGPT-5.6 Luna. Other paid proprietary including Gemini and xAI are 9.8% of token share and 27% of revenue share. Open Source Removing Closed Sourced and Free Tokens. A majority of OpenSource is hosted on-prem meaning that enterprises deploy their own inference stack onto bare metal. When I say bare metal I mean bare metal + kubernetes. This is 19.5% of global token share but 54% of non-free Open Source. The portions of the market that are available to AI Platform and Neoclouds are 1.5% OpenRouter and 14.6% of Hosted not OpenRouter. This leaves OpenRouter as 10% of the market available to AI Platform / Neoclouds. Although OpenRouter is not an accurate representation of total LLM token consumption, it's a decently accurate estimate of Open Source AI Platforms / Neoclouds. Top AI Platforms Most AI Platforms serve DeepSeek V4 and GLM 5.2, but many do not serve Kimi K3 because Kimi K3 requires a revenue share agreement. OpenRouter keeps track of token market share on a 1-day window. Having track those windows over the past week, it's clear that the leading AI Platforms by market share are FireworksAI, Coreweave ($CRWV). Contenders include Modal, TogetherAI, NovitaAI, StreamLake, GMICloud, Digital Ocean ($DOCN). Nebius ($NBIS) did have market share in Kimi K3 and had 0.6% market share at one point but had dropped out since they had not implemented KV cacheing yet (2). Bare Metal + Kubernetes People call it bare metals but almost all bare metal includes software in that Kubernetes is included. So yes, techically every Neocloud, $CRWV, $NBIS, $IREN sells software with all their GPUs. Yes $IREN has had Kubernetes before Mirantis as they were/are selling to AI Startup HumeAI. What Mirantis brings is orchestration, not Kubernetes. However, what we actually want to know is how much of the market is higher level software services aka SaaS/TaaS? The answer is the market is mostly bare metal (IaaS) with some PaaS. Even 70% of $MSFT AI revenue is bare metal with possibily some PaaS to OpenAI (3). You can bet a majority of AWS AI revenue is to Anthropic. Oracle is a large part to OpenAI and GCP sells alot of Anthropic. Many Enterprises from Netflix, Uber, to startups like Cursor, Perplexity, FigureAI all work on IaaS+Paas. The latter 2 are $IREN customers and the former is a $CRWV and $NBIS customer. Most likely Shopify and Cloudflare work on IaaS+PaaS as Shopify utilizes both GCP + $NBIS and Cloudflare utilizes both $CRWV + $NBIS. Mirantis enables $IREN to do IaaS+PaaS which is the majority of the market. If need be, many of these AI platforms dedicated to inference will be on sale to consolidate in the next 2-4 years and $IREN will be able to pick one up for ~3-10B.

  • hexTerminator24
    hexTerminator (@hexTerminator24) reported

    @ECHIDNAenjoyer @FriendInsideMe5 one day the prequel site just exploded and refused to work, it would show a "site is broken" screen from cloudflare. and apparently, the last backup was from the update right before a huge flash [S] page, which became known as "purrgatory" due to the long wait.

  • ptremblay
    Philippe Tremblay (@ptremblay) reported

    @levelsio btw, would you be interested in paying me a meager salary. something like 45k USD a year (but 50% equity) for building a Railway competitor. I just find they have really nice product/service offerings. I feel about the same about it as I do regarding CloudFlare. Seems brilliant to me.

  • CyberTechWolff
    πŸ”₯πŸ΄β€β˜ οΈCyberTechWolfπŸ΄β€β˜ οΈπŸ”₯ (@CyberTechWolff) reported

    @interesting_aIl Why they got a phobia of bots on the Internet and we have to ******* use newer Operating Systems just to visit a ******* website? I think cloudflare is full of ******* **** if that was the case you wouldn't have to verify if you're a "bot" each website you ******* visit.

  • Deathlyrage
    Alderon Matt (@Deathlyrage) reported

    @xlab_os I asked cloudflare enterprise team on a call how they could be sure i wouldnt have data loss on R2. They had zero good answers, never going to use the service.

  • jedisct1
    Frank (@jedisct1) reported

    @InSysOut @Cloudflare False positives have always been an unsolved problem in the security industry. But failing to review them, or simply ignoring customer reports, is an even bigger problem.

  • cozybearlog
    μ½”μ§€λ² μ–΄ 🐻 CozyBear (@cozybearlog) reported

    Cloudflare says bots now generate up to 1,000 times more traffic than humans. The headline reads as dystopia. The engineer in me reads it as a pricing signal. Every bot request is a business transaction. Who pays for the 1,000x? The answer decides which platforms survive. If the cost lands on the bot operator, agent economics change overnight. If it lands on the platform, we all pay more for everything. The real story is not humans becoming a rounding error. It is that the internet economy is about to get its first native machine-to-machine billing layer, and whoever owns it owns the next decade. CAPTCHAs were the beta version of this. The full version is metered identities for machines.

  • KorraFinance
    Korra AI (@KorraFinance) reported

    @StockSavvyShay The engine for that growth is already running: 57.5% of all web traffic is now automated bots, per Cloudflare. The biggest customer for cloud infrastructure won't be humans using AI; it will be AI agents themselves. That's the real capex supercycle.

  • theozbuilds
    Oz Wadood (@theozbuilds) reported

    @arvidkahl @nickgraynews have you considered rate limiting or a reverse proxy like Cloudflare in front of your API? we've had similar issues scaling Podscan-type products, and limiting by IP/API key early saved us thousands in compute costs.