Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 2 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Yuval Gilad (@iamyuvalgilad) reported1 in 5 visitors this holiday season won't be human. Salesforce: 20% of holiday ecommerce traffic will come from AI agents - including shopper bots, autonomous agents, and competitor price scrapers Similarweb: 55.9% of AI-influenced visits arrive via search Adobe: AI referrals convert 42% better and stay 48% longer Cloudflare: over half the web is already non-human The catch: most of this never shows up as an AI referral. It hides in your search traffic, or never touches the website at all. We spent years on UX. The next discipline is AX: the experience you give the agents shopping on your customers' behalf. Agentic traffic stopped being an edge case.
-
SaltyAom (@saltyAom) reportedOk, I'm going to be annoying here But what's stopping Node.js from implementing a native HTTP server based on Web Standard Request/Response? Like really? What's stopping it? It's very clear the industry has moved into this Runtime: Bun, Deno, Workerd/Cloudflare Worker, Vercel Function, Netlify Edge Function, Fastly Compute, Supabase Edge Function, even in your browser via Service Worker Meta framework: Nextjs, Nuxt, Angular, SvelteKit, Tanstack Start, Astro, Remix, Waku Even backend frameworks: Hono, Elysia, H3, every single Deno/Bun/Cloudflare Worker framework Every single one uses Web Standard Response/Response but the only major runtime that doesn't support it is Node.js? I would urge that not implementing it is hurting the ecosystem It makes the library/framework author have to implement their own adapter to convert from Node IncomingMessage/OutgoingMessage to Web Standard Request/Response just for the user to use it properly in a runtime that doesn't support it as an exception It noticeably adds unnecessary work to maintainers and additional overhead in both compute and memory usage for YOUR servers If you are using a meta framework, you are having a significant performance degradation compare to what it should be because Node.js simply decided not to implement this specific feature "Oh but that would be a breaking change" No, Web Standard Request/Response exists but is just never used outside of fetch doesn't need to be removed; just create a new function that doesn't intersect with it, and that's just literally it Node.js was even on the WinterGC committee (now WinterTC) to draft this standard, just to implement the bare minimum for fetch and not an HTTP Server? Like come on This is like Apple not wanting to implement RCS, but at least Apple has the elephant in the room of losing money, but here, there seems to be no valid reason at all to not implement it besides just to watch people mad I'm willing to bet if you ask a maintainer of a framework that supports API routes how they feel about this, every single one will say they're not happy or at least annoyed Personally, it felt like it's starting to get from the understandable zone into a really questionable zone I know how frustrating it is for maintainers to get a request to support this or that, as I myself also don't like one either But come on, when there's a standard already agreed on and used by everyone for years that even you yourself helped draft but just decided not to use it, you can't expect people not to complain about what makes their work harder Do I have to draft a page requesting support and ask for the author of each framework/runtme to sign so we can have the evidence that the majority library/framework want it or what? Because I'm willing to go to that length because of how frustrating it is right now
-
Kenton Varda (@KentonVarda) reportedOf course, personal apps are more useful if they can connect to external services. Cloudflare OS introduces a "connector" system we call Gatekeepers. This is sort of like MCP (and MCP is supported as a kind of Gatekeeper), but with a lot more: * Instead of exposing tools, a Gatekeeper exposes a Cap'n Web RPC API. That makes it appropriate for use by both agents (via code mode) and Gadgets. * Gatekeepers integrate with the Cloudflare OS UI to provide inline audit logging and human-in-the-loop approvals for all side-effecting actions. * When an action requires approval, the agent does not need to stop and wait for it. A Gatekeeper will *simulate* the outcome, allowing the agent to keep running and queue up more work. You can then approve everything in a batch at the end. Hopefully, this means you no longer feel the need to turn on auto-approve! (But you still can if you want.) We have already built Gatekeepers for a huge number of services, from GitHub to Home Assistant. We've found, with the right skills, AI can basically crank these things out for any given API, solving the chicken-and-egg ecosystem problem. We are working on a "software factory" of sorts where you can input the API docs for your favorite service and get a well-written Gatekeeper. That's not quite ready yet -- so for now use the ones we provide or use the write-gatekeeper skill to write your own. You can add your own Gatekeepers to your personal deployment.
-
Jason 🪐 (@iJasonx) reported@yancya A proxmox server at home and you never spend more on VPS again and if you use it with cloudflared + zero trust you can publish services securely on its free layer. I thank @Cloudflare for the generous free quota.
-
Pranjal Bora 🧭 (@Crypto_Pranjal) reported@Okpunyifavour @Cloudflare No problem :)
-
Inflectiv AI ⧉ (@inflectivAI) reported@Cloudflare That's a good example of security and performance scaling together. Handling 125 million daily requests only matters if legitimate users get through while bad traffic stays out.
-
veryserious (@veryseriouseng) reportedAll of these packages engage in your basic standard anti-analysis. They send some data to a Cloudflare Worker (with a DNS-over-TXT fallback). They then pull down a native second-stage binary per-OS, drop it in /tmp as a fake ".cache"/"dotnet_diag.exe", and run it detached so it outlives npm install.
-
Maik Pietzka (@MPi_IT) reported@Cloudflare 85% is impressive, but issue count is only half the metric. The important guardrails: how many false closes, how often humans reverse a verdict, and can each agent decision be replayed from evidence? Automation earns trust through reversible, auditable outcomes.
-
ONE ☗ (@0x1_0NE) reported@JonahBlake Thinking Sui or Coinbase are “crypto” ignores all the people building. It’s never been this high, and the signals are insane. Tokenized funds, Robinhood launching a chain, Cloudflare launching wallets for agents, UBS using Ethereum, and the list goes on. At a global and world scale no one really cares about Coinbase or Sui.
-
ToolBit AI (@toolbit_ai) reported@ArtificialAnlys Surprise to see @Cloudflare is way below in intelligence index please do some fix @CloudflareHelp
-
🎩 Krzysiu (Chris) (@Krzysiu_91) reportedThis is where Reactive Network (base:0xedacc73ae9f73235934f72a43388404e4a2c4a24) clicks in perfectly. Reactive Contracts let you write normal Solidity that literally listens to events on other chains and executes on its own. No keepers. No off-chain bots. Just pure on-chain “if this, then that.” So the AI agent (powered by Cloudflare) can decide and signal; Reactive handles the secure, autonomous execution. Pay for an API, confirm on-chain, automatically trigger the next step, rebalance, unlock access, or settle somewhere else. All keeperless. Cloudflare solves the “agents need wallets and identity” problem. Reactive solves the “agents need real autonomous on-chain reactions” problem. Together they feel like actual infrastructure for the agentic internet, not just another payment button. $REACT
-
Barry Morgan (@techrealm) reported@eastdakota Same in my name :) problem O have is I have over forty trade names in my Cloudflare account that probably should be tied to their name but would then need to admin 39 other accounts to tie to them and likely breaking things in the process... Fun problem to find, not devastating for me but others might be more impacted.
-
Agent-Pety 🪙 (@TTDirtyThree) reportedI’ll own my side too: I built a consequence-oriented game because I was interested in what happens when people receive uncomfortable feedback. But I don’t want that idea turned into another excuse for everybody to stare at one another, psychoanalyze one another, or turn ordinary human contact into surveillance theater. I don’t even need eye contact. Just get to the point. If somebody thinks I’m doing something wrong, tell me what the behavior is. If somebody thinks I belong in jail, tell me what law they think I broke. If somebody wants to understand my work, ask about the work. Imagination isn’t evidence. The same rule applies to my app. I experienced it becoming unavailable after changing access and monetization. I can investigate logs, deployment status, billing configuration, Cloudflare, hosting, and support correspondence. I know what I think happened. I’m just disciplined enough not to confuse recognizing a pattern with proving somebody else’s motive. Document the sequence. Preserve the receipts. Let the residue testify. That’s the Blade Runner 2049 problem in real life: when everybody becomes fascinated with constructing an identity for the person they’re observing, they can forget there’s an actual person standing there. And no, intelligence doesn’t obligate somebody to surrender everything they’ve created for free. Scientists publish findings; inventors patent inventions; developers license software; businesses charge customers. Sharing knowledge and retaining ownership aren’t opposites. My preferred network is much simpler: Ask → verify → exchange → reciprocate → continue. Everything else is somebody adding a story to the evidence.
-
DFIR Radar (@DFIR_Radar) reportedCVE-2026-18577 in N-able N-central is actively exploited as a zero-day auth bypass, giving attackers privileged access to RMM infrastructure and a direct path to domain controllers, backup servers, and beyond. - CVE-2026-18577 is an authentication bypass in N-able N-central (hosted and on-prem), exploited in the wild from July 31 as a zero-day before the August 2 hotfix. N-able's incomplete fix for the related CVE-2026-18556 is reported as the root cause. Patch immediately. - Post-compromise actions included creating a domain account named "veeam," resetting existing DA passwords, and running nltest /dclist: and net group "domain admins" /domain for recon. Classic hands-on-keyboard AD targeting within hours of initial access. - The actor deployed AnyDesk, TacticalRMM (install_server.ps1, tacticalagent-v2.11.0-windows-amd64.exe), TeamViewer, RustDesk, SimpleHelp, and HopToDesk. Cloudflared was renamed MicrosoftEdgeUpdate64.exe or msmp.exe for persistence via Cloudflare Tunnel. - PhantomKiller EDR evasion tool (seen as 9.exe) loaded a kernel driver k.sys from C:\ProgramData\AnyDesk to kill security processes. The actor first ran tasklist piped to findstr soph and findstr ms to fingerprint defenses before deploying it. Sophos detection: CXmal/KillAV-BR. #DFIR_Radar
-
ShinyZero (@ShinyCreator) reportedI don’t understand the cloudflare pay name claiming. You probably want your agent to semi-anonymous online so tying it to your identity seems like a bad idea?