Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Paris, Île-de-France | 1 |
| New York City, NY | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
| Noida, UP | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
TechRemarker (@TechRemarker) reported@CloudflareHelp Does any one know how to contact @Cloudflare support? As detailed in this thread. CF had a bug where they charged me twice for the domain registration. Site contact options just show help docs. No response from CF Help here. Anyone know how I can reach them?
-
Kevin Gray (@graykevinb) reportedThere are a ton of open fall internships rn. You should go apply. Google jobs sucks. Check companies directly. Also checkout handshake. Cloudflare and Tesla are hiring fall interns. You should apply ASAP. I will as usual be skipping this round but if you want help with your resume lmk. I have a somewhat decent success with applicant tracking algorithm manipulation. If you need money some are even 40hrs a week and pay $50/hr
-
Volt ✚.🏳️🌈 (@voltreaver) reportedit feels like adolf hitler made cloudflare warp to be the most unusable **** ever why does it keep disconnecting randomly
-
Matt (@meszmatew) reportedIs anyone else having issues with cloudflare billing?
-
brendan (@brendonovich) reported@thdxr i've never used cloudflare until alchemy existed, i'm scared of wrangler configs
-
DFIR Radar (@DFIR_Radar) reportedMicrosoft's Q2 2026 email threat roundup: 7.6 billion phishing threats detected, Tycoon2FA volumes collapsed 92% post-disruption, and Teams-based vishing hit 10x the mid-2025 baseline. Key findings: - Tycoon2FA never recovered after March's DCU-led infrastructure action. Monthly volume fell from a 15.1M baseline to 1.2M by June, an 92% decline. The platform shifted to .RU TLD hosting after losing Cloudflare, but its share of CAPTCHA-gated phishing dropped from 76% peak to 12%, and QR code campaign share fell from 33% to 14%. No replacement PhaaS emerged at scale. - Teams vishing is the sharpest growth vector this quarter: weekly malicious call attempts rose 80% since January 2026 and now run at nearly 10x the mid-2025 baseline. Attackers impersonate IT helpdesk, peak 14:00-20:00 UTC Mon-Fri, and increasingly use generic display names (52% in June) rather than obvious IT branding, likely blending with ClickFix-style lure themes. - Two notable campaigns: a June 1 BEC wave hit 67,000 users across 42,000 orgs in under 3 hours using Python email.mime, Amazon SES API, DKIM-signed ecajovna[.]sk, and reply-to domains ilyff[.]com, j-gmails[.]com, x2mails[.]com. A June 14-15 campaign hit 107,000 users using nested EML, ICS calendar invite, a silent OAuth redirect through login.microsoftonline[.]com, and a BAT dropper (Financial_report.bat) pulling installer.exe from pixeldrain[.]com. #DFIR_Radar
-
Lewis N Watson (@LewisNWatson) reportedreally appreciate what cloudflare do but the chokehold they have over the internet is net negative. msft have similar issues.
-
Duane C (@DuaneC6) reported@CryptoCyberia The internet was never a system of tubes, it has always been 500 micro-services pointed at each other like loaded firearms. People on remote, nearly-uncontacted islands know when Cloudflare goes down, and now it goes down all the ******* TIME.
-
Vlady Veselinov (@vladinator1000) reported@thdxr What specifically can't you do with IaC? Maybe someone at Cloudflare can help? @dillon_mulroy do you know someone who works on Wrangler?
-
Santosh Yadav (@SantoshYadavDev) reported@thdxr I never got comfortable using wrangler, I think I dont like it. otherwise cloudflare has a great DX
-
Milk Road AI (@MilkRoadAI) reportedOpen-source is dying and the companies that survive it are about to get very rich (Save this). That's the uncomfortable truth in Dylan Patel's take, American open source AI is basically dead. Meta has gone quiet on Llama, Mistral, once the loudest open source advocate in the West, shifted its flagship models to proprietary licensing while charging five to ten times more than comparable Chinese models for similar performance. So the only frontier level open models left are Chinese, Qwen, DeepSeek, Kimi, GLM and the labs building them barely profit from giving them away. The money instead flows downstream, to whoever hosts, serves and charges for access to those free weights. Qwen overtook Meta's Llama as the most downloaded model family on Hugging Face in 2026, and Chinese open models now out download American ones globally by a wide margin. Kimi K3 was ranked the top open source model in the world by LMArena. None of that revenue lands with the Chinese labs themselves but rather lands with the inference layer running on top. Inference is already the biggest chunk of the AI compute market, with cloud inference alone estimated near $50 billion in 2026 and growing around 60% a year, dwarfing training infrastructure spend. Token pricing has collapsed roughly a thousandfold over three years which sounds bad for margins until volume growth outpaces the price decline, keeping total inference revenue climbing. Mistral's own pivot away from open weights shows what happens when a lab tries to charge premium prices in a market Chinese competitors are commoditizing its newest model is losing on both cost and quality to rivals a fraction of the price. If Chinese labs eventually decide there's no financial reason to keep releasing frontier models for free, the open-source pipeline could dry up overnight. However, here are the publicly traded infrastructure plays positioned to benefit if open source continues to dominate. Nebius provides the same raw compute layer underneath inference demand, without needing to bet on any single model's survival. AMD is chasing that same inference chip opportunity with its MI series accelerators, positioning itself as the main alternative supplier once inference volume keeps compounding. Cloudflare (NET) benefits through its Workers AI platform, which increasingly serves as the delivery layer pushing open weight models out to edge devices and apps cheaply. Microsoft (MSFT), Amazon (AMZN), and Alphabet (GOOGL) all benefit as the hyperscalers whose cloud platforms host the bulk of enterprise inference workloads, collecting compute revenue no matter which model an enterprise ultimately runs. Milk Road Pro is tracking all the biggest beneficiaries of open source AI, if you want access to all our AI trades around this trend, you can come join us for just $1 using the link below!
-
David Frosdick (@DavidFrosdick) reportedCloudflare Email then sends the customer a link to a watch page. They can react, or reply, and that comes back into D1 against the original order. Whole loop, no third-party service in the middle.
-
Panat (@ptaranat) reported@LevJampolsky @Teknium you're better off implementing a simple version of this. give each trust tier its own hermes profile with toolsets stripped in config (platform_toolsets, agent.disabled_toolsets). then you expose only the api_server, and let ur own app authenticate the user and broker ever call. hermes' shared API key reads every session on the instance so it never accepts a session ID from a client. you'll want to map the user to the session in a DB and translate server side. and also put a Cloudflare Tunnel + Access service token in front so the agent host doesn't open any inbound ports. something like this took me one afternoon.
-
Anjula Dwivedi (@HeyAnjula) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked.
-
Xuanwo (@xuanwo) reported@tison1096 @Cloudflare do you want to build a *** host service?