Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Paris, Île-de-France | 1 |
| New York City, NY | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Leo (@0xGKBRK) reported@FuckKoroks It’s not like Cloudflare puts itself in the middle by hacking the website. The person running the website wants to use Cloudflare. If you’re gonna complain to someone, complain to the website that subjects you to that crap. Or vote with your wallet and go to a normal website.
-
Abdulkadir | Cybersecurity (@cyber_razz) reportedOn June 3 2026 Cloudflare CEO Matthew Prince announced that bot and agentic AI traffic had officially surpassed human generated web traffic for the first time in the internet's history. The split landed at 57.5% bot traffic versus 42.5% human traffic. Prince had originally predicted this crossover would happen by end of 2027. It arrived eighteen months early. His response was direct: "Welp, that happened faster than I predicted." The driver is not the old wave of scraper bots and search crawlers. The main culprit is agentic AI. Autonomous programs browsing the web on behalf of AI assistants. A single agent can visit thousands of pages to complete a task a person would finish in a handful of clicks. Agentic AI traffic grew 8,000% across 2025 alone. Now let’***** on the Dead Internet Theory context. The theory, which originated in fringe internet forums around 2021, proposed that most internet activity was already artificial. Fake engagement, bot generated content, astroturfed discussions, AI personas. The humans were the minority and did not know it. The conspiratorial version of that theory claimed it was coordinated and intentional. That part remains unverified and unlikely. But the core observation that the majority of internet traffic is non-human is now confirmed data from the largest internet infrastructure company on the planet. The internet was architected around human usability and attention. The entire world of digital advertising, publisher monetisation, and e-commerce sits on the assumption that users are human. That assumption is now statistically false. Every engagement metric, every analytics dashboard, every ad impression count is increasingly measuring machine activity and reporting it as human behaviour. The business models built on human attention are being quietly hollowed out by traffic that generates requests but never buys anything, never reads anything, and never remembers what it visited. The theory was wrong about the why. It was right about the what.
-
Publisher in a Box (@publisherinabox) reportedMost publishers will see "charge AI bots to crawl your site" and think revenue. It is not a revenue decision. It is a visibility decision. And the wrong call can erase you from the answers your audience is already reading. Here is what happened. Cloudflare launched pay-per-crawl in July 2025. AWS added the same capability to its firewall on June 15, 2026. Two of the largest infrastructure companies on the web now sell a toll booth for machines, built on HTTP 402, a status code written in 1997 and left dormant for nearly three decades. The background matters. For three decades the deal was simple: let the crawler in, it indexes you, it sends people back. AI crawlers kept the first half and dropped the second. Cloudflare's own data shows training accounts for nearly 80% of AI bot activity. The search-purpose fetches that can actually return a citation are a small slice of what remains. Most of the crawling is pure extraction that sends nobody back. So a toll booth sounds fair. And for certain publishers it is. If you own a deep, licensable archive, a reference database, or proprietary data sets, and your distribution does not depend on those crawlers, charging makes sense. Your content is genuinely worth paying for and you can afford to refuse bots that will not pay. But here is the part the launch announcements leave out. For publishers whose strategy depends on being the answer an AI agent gives, the crawler IS the distribution. Wall it out and you might collect a few cents while deleting yourself from the place where your audience now asks questions. Adobe's 2026 data showed AI-referred traffic to US retailers up 393% year over year. The crawler you would charge and the answer engine that refers a visitor to your site are often the same pipeline. The operator move before you charge anything is to watch the door first. Find out which AI bots actually reach your site and what they take. Separate the ones that feed answers and send referrals from the ones that extract content and return nothing. Then meter one bot on one path and watch what happens to both crawl volume and your presence in AI-generated answers. Let the data inform your policy, not the hype. No public study has yet shown how much citation share a site actually loses by tolling a specific bot. The logic of the cost is sound, but the magnitude is unknown. That is why this stays a decision you make on your own data, not on a rule of thumb. One more thing worth noting for publishers building diversified businesses. Your Facebook page, your website traffic from Google Discover, your newsletter list, and your presence in AI answers are all real audiences with real economics. AI citation is the newest of them and it is growing fast, which is exactly why the publishers who start showing up in those answers now are the ones building an edge before the rest catch on. The operators who win here are the ones already running multiple discovery channels and adding this one while it is still wide open. The toll booth is real. The choice is yours. Before you meter a single bot, know which of them are the ones putting you in front of your audience, and treat your spot in those answers as an asset worth keeping.
-
Panat (@ptaranat) reported@LevJampolsky @Teknium you're better off implementing a simple version of this. give each trust tier its own hermes profile with toolsets stripped in config (platform_toolsets, agent.disabled_toolsets). then you expose only the api_server, and let ur own app authenticate the user and broker ever call. hermes' shared API key reads every session on the instance so it never accepts a session ID from a client. you'll want to map the user to the session in a DB and translate server side. and also put a Cloudflare Tunnel + Access service token in front so the agent host doesn't open any inbound ports. something like this took me one afternoon.
-
NetAskari (@NetAskari) reportedBased on that info it quickly builds a list of over 600 python scripts and sh files starting a full chain of recon and exploit measures. It logs all its operations, success rates and outcomes. From SQL Injections, http smuggling, race condition probing, cloudflare bypass, WAF evasion, cache poisoning etc. Its attack angles are pretty wide. None of the scripts or methods seems particularly clever but if a 'fire and forget' solution is what you are looking for, than this is not too bad. 4/6
-
Ray 🇺🇦🏳️🌈 (@uasneppy) reportedI’ll try to fix snepclub twitter embedder later today, sorry :( I didn’t know about the new updates and me having to have a burner account, plus deploying it on Cloudflare 💀
-
Mat Diekhake (@thedekeofhazard) reportedYesterday, I set up Cloudflare for my websites. It made them slow, and I had to turn it off. It also claimed my sites were down at the host several times.
-
DR.PIXEL (@pixelpatchit) reportedSwapdesk Alpha: DNS Expansion and Reliability Improvements As Swapdesk Alpha continues to mature, we plan to expand beyond our current Cloudflare and Google DNS support by adding additional DNS provider options. These providers have given us a strong foundation during the alpha phase, allowing us to focus on building and testing core functionality while maintaining reliable connectivity. During the THORChain swap process, users may occasionally experience intermittent connection issues while the application is retrieving required swap information, such as the deposit address needed to complete a transaction. These issues are not consistent and do not occur during every swap, but when they happen, they can create confusion because they occur during an important step in the transaction flow. It is important to clarify that an error message during this stage does not automatically mean a transaction has failed or that funds are at risk. In many cases, the issue is related to communication between the application and supporting services, which may include DNS resolution, API availability, network routing, or other connectivity factors. To improve reliability, future versions of Swapdesk Alpha will introduce broader DNS support, improved fallback handling, and additional resilience measures. The goal is to provide users with a smoother experience, reduce unnecessary interruptions, and ensure that Swapdesk remains dependable as adoption grows. We appreciate the feedback from early users helping identify areas where reliability and user experience can continue to improve
-
Sample (@sample) reportedCloudflare suffers a parity issue where platform features/runtime configs are Wrangler-only; omitted from native API/Terraform providers. So one can't choose purely declarative IaC or pure Wrangler; they're forced a hybrid & IaC tools have to shell out to Wrangler CLI subroutines
-
The Holyheights 🇰🇪 (@the_holyheights) reportedPeople are launching apps to real users while skipping the unglamorous work that quietly sinks them. Here is the essential pre-launch checklist every AI builder should run through. Don’t skip these steps: 1. Protect yourself, not just your product. The second you start collecting user data, you’re operating under real legal requirements (GDPR, CCPA, etc.). Publish a privacy policy and know exactly where that data lives. 2. Enable Row Level Security. Without RLS, anyone can open DevTools and read your entire database. In Supabase, go to Auth → Policies. Zero policies = your app is completely exposed. Fix it in five minutes. 3. Test the failure paths, not just the happy path. Wrong password five times in a row. Password reset for an email that doesn’t exist. Verification link clicked twice. Signing up with an email that’s already registered. These catch roughly 80% of auth bugs. 4. Establish a security baseline in two minutes. Prompt your AI: “Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture.” 5. Check against OWASP. Prompt: “Review my app against OWASP standards and highlight vulnerabilities.” This is where SQL injection, XSS, and authentication flaws actually surface. 6. Client-side validation is UX, not security. Attackers simply disable JavaScript and hit your API directly. Always validate again on the server—every single time. 7. AI-generated code commonly leaks data in three places: .env values ending up in the frontend, API responses returning too much information, and secrets appearing in logs. Prompt: “Check my app for credential or sensitive data leaks in frontend or API routes.” 8. API keys in the frontend = game over. If it’s visible in the browser, assume it’s already compromised. Move it server-side or proxy the request. 9. Add rate limits before someone burns through your API budget. Cap every endpoint that hits a paid service. I’ve seen a Supabase bill jump from $20 to $200 in a single day. 10. Put CAPTCHA on public forms (Cloudflare Turnstile is free) and lock CORS to your own domain. Ten minutes of work that stops most bot floods. 11. Error messages that don’t leak information. Show “User not found,” not “SELECT * FROM users failed.” Log the full technical details server-side and give users only generic messages. Build fast. Just don’t ship unprotected.
-
swisscheese (@swisscheese4299) reported@OpenAI image generation is still throwing intermittent 520 errors through cloudflare.
-
VICTOR (@victoris_x) reported@TheRealAdamG I tried it with Crunchyroll but Cloudflare verification stopped me from login.
-
The Agentic Operator (@AgenticOperator) reportedSeptember 15. 52 days from now. Cloudflare changes its default AI crawler settings. If your site is on Cloudflare and you do nothing, AI might stop reading your pages. Training and agent crawlers get blocked by default on ad-supported pages. That includes ChatGPT's live fetch bot and Claude's real-time crawler. Here's the part that should scare you. Googlebot crawls for both Search and AI training in one bot. Block training crawlers and you might block Googlebot too. On accident. Because of a setting you never changed. Cloudflare's CEO confirmed this week that bot traffic has now passed human traffic on the internet. More machines read your site than people do. And in 52 days the biggest CDN on the planet changes who gets in by default. Check your Cloudflare dashboard. Security settings. AI crawler controls. If you haven't touched them, they're about to touch you. Most site owners don't know this deadline exists. The ones who miss it won't know they're invisible until the pipeline dries up months later.
-
Polymarket Alpha (@Polymarketalpha) reported🚨 JUST IN: Bots now generate more web traffic than humans. According to Cloudflare, bots accounted for 57.5% of global web page requests in June 2026, while human traffic fell to 42.5%. This marks a historic turning point for the internet. AI crawlers, automated systems and intelligent agents are no longer a minor part of the web—they are becoming its dominant users. Cloudflare’s CEO had previously predicted that bot traffic would not surpass human traffic until 2027. Instead, the milestone arrived a year early. The internet is rapidly shifting from a network built primarily for humans to one increasingly accessed, indexed and operated by machines. Technological progress—or the beginning of a less human internet?
-
Grigori Karapetyan (@GregKara6) reported@weswinder no its not brother that's misinformation disseminated by a certain "competitor" hence why i call it a mind virus. i have never ran next.js anywhere but serverless, ok thats a lie but 99% of the time i have ran it serverless. and no not on vercel. i run my apps on digital ocean app platform (equivalent to serverless like lambda) and lambda itself. if you mean cloudflare workers. thats not serverless, that a totally different runtime running on v8 js engine, and by design *does not run node apps* in other words, ANYWHERE where node runs, next.js also runs with 0 modification or setup. the only thing that is vendor locked, which is the wrong thing to call it anyways is the vercel *specific* features like image optimization and SEO which is... on top of that, next.js has had the adapters api since 2019, just in case you want to go in and change the build process, but this does not matter and you probably will never ever need it.