1. Home
  2. Companies
  3. Cloudflare
  4. Outage Map
Cloudflare

Cloudflare Outage Map

The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below

Loading map, please wait...

The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.

Cloudflare users affected:

Less
More
Check Current Status

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Most Affected Locations

Outage reports and issues in the past 15 days originated from:

Location Reports
New York City, NY 2
Los Angeles, CA 1
Paris, Île-de-France 1
Manchester, England 1
Check Current Status

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • aronchick
    David Aronchick (@aronchick) reported

    @QuinnyPig @Cloudflare @vercel When do **** posts get their arn

  • zlxndr
    Alexander Zuev (@zlxndr) reported

    @vicentesandev + retries, timeouts, DI, error taxonomy is trivial and not an issue even without effect - the only core reason for me to consider the transition is to make the logic more maintainable and more reliable And the most confusing bit of this is handling errors / translating them at the boundaries: - tanstack server fn handle them one way - server api routes expect a response - cloudflare workflow have specific control flow requirements with nonRetryableError - cf durable objects have their own nuances with alarms - cf queues need to ack/retry - cron just logs at the boundary That’s where probably most of integration effort lies

  • FabriceNEYRET
    Fabrice NEYRET - pro (@FabriceNEYRET) reported

    @KaleyGoode cloudflare is ultra-annoying but usually you can log-in ! (from time to time you need to re-confirm identity once logged + and some days ago the site was down, though). BTW it seems that the unofficial plugin is (sometime?) incompatible with cloudflare.

  • faye_xiao_
    Faye Xiao (@faye_xiao_) reported

    The spirit of Spirit just sold for $10 million Google is buying Spirit Airlines' data out of bankruptcy. Emails, internal communications, spreadsheets, bookings, frequent flyer and HR records, all de-identified, for $10 million. Judge Sean Lane rules on the sale Wednesday. The obvious read is that Google wants more data. But de-identified data doesn't work for advertising, since you can't target someone you can't name, and Google already sees more airfare information through Google Flights than Spirit ever generated internally. An airline that went under in May is also a strange place to look for pricing wisdom. What's worth buying is the internal material. The emails and the spreadsheets they reference record how work moved through the company: a question gets asked, a document gets built, a decision gets made, a system gets updated. Consumer text is everywhere, and records of how an organization actually functions are not, which is what you need if you want models that operate inside workflows rather than talk about them. Google's own statement uses the word enterprise, and the runner-up bid of $7.5 million came from Mercor, a company whose entire business is sourcing training data for AI labs. When the second bidder isn't another airline, the market has told you what was being priced. The strange part is that Google isn't short on this data at all. It runs Gmail and Workspace and sits on possibly the largest collection of business correspondence in the world, and it has promised enterprise customers it will not train on their content, which is not a promise it can quietly break. So it has the material and no permission to use it. What $10 million buys is clean title, a court approved dataset nobody can sue over, at a moment when everyone else is defending scraping claims. Dead companies can agree to things live ones can't. Any of this is worth paying for because the public supply is running down. Epoch AI's 2024 analysis put the stock of quality public human text at roughly 300 trillion tokens and projected it would be consumed between 2026 and 2032, a window that opens this year, and access has closed faster since than the arithmetic alone suggests. A census of the top 100,000 domains this July found 19.1% blocking at least one AI crawler, and in September Cloudflare begins blocking mixed use crawlers by default across its entire free tier. Private operational records are the obvious next reserve, and they are almost untouched. Epoch left them out of its estimate because private data is fragmented and legally too messy to use at scale, which is precisely the condition a bankruptcy court removes. That makes Wednesday's ruling more interesting than the sale. If it goes through, every bankruptcy from here has a new asset to offer, and the value will depend on how well documented the industry already is. A corner store has nothing worth buying, since you can watch how it works from the sidewalk. A hospital or a law firm is the opposite, because even with names removed the record shows how a case moves through the organization, who escalates what to whom, and which exceptions get made. That knowledge lives in internal systems and in people's heads and appears nowhere public. The catch is that the supply is biased toward failure, since no healthy company would sell its internal record, so every dataset that reaches the market comes from an operation that didn't work. That's useful for learning how a process runs, and much less useful for learning what good judgment looks like.

  • splamei
    Splamei Ch.【 SplameiPlay 】 (@splamei) reported

    Yes I am reading the full Terms of Service and Privacy Policy to Cloudflare. Why do you ask? I'm not weird

  • Southofpaw
    Southpaw | ZZZ Optimizer v6 is LIVE (@Southofpaw) reported

    @JaIdabaoth Nevermind sorry just checked enka and it’s up. I might need to check cloudflare to see there’s an issue

  • OgFyaz
    FYAZ (@OgFyaz) reported

    🚨 A Spectre attack leaked a JWT from a co-located Cloudflare Worker. Researchers demonstrated the attack in Cloudflare’s production environment at up to 12 bits/second, 360× faster than the 2021 result. No customer data was accessed. Cloudflare says the attack is now mitigated. Thoughts?

  • jgwifi
    Joshua Gardiner (@jgwifi) reported

    @Cloudflare Hope you can help. I was double charged for a registrar change. Attempted to open a ticket but the support platform says no tickets for my free account. I asked the AI bot, it says I should be able to open a ticket. Any advice? :)

  • Iamhuman_ORBS
    ORBS Official (NASDAQ: $ORBS) (@Iamhuman_ORBS) reported

    @Cloudflare reported on July 1 that more than half the traffic it sees across its network is now non human. AI training crawlers went from 22% of crawler requests in spring 2025 to 52% by June 2026. In some heavily crawled sectors, human traffic fell by as much as 40% in under a year. @worldnetwork's World ID answers this at the person, not the packet. Verify once in person at an Orb. Carry a private proof you are a unique human. The proof travels, your identity does not. $ORBS holds 301.9M $WLD, ~8% of circulating supply, the largest publicly disclosed institutional position globally. $WLD is the token that powers the World ID proof of human network.

  • s41r4j
    S41R4J (@s41r4j) reported

    I recently ran into an interesting Cloudflare Turnstile issue while looking at abuse hitting my own domain/server! One thing that surprised me: The Turnstile sitekey is public by design! That does NOT mean someone can directly bypass Turnstile just by having the sitekey; But this is where it gets interesting! An attacker can take: `your domain + your Turnstile sitekey` and feed it into CAPTCHA-solving infrastructure to obtain a real, valid Turnstile token! So the flow can effectively become: sitekey → automated solver → valid token → protected endpoint The attacker is not breaking Cloudflare, they are simply solving the challenge at scale! "Which means Turnstile should never be treated as the entire security layer!" Your backend should still: • Verify every token using Siteverify • Validate the hostname • Validate the expected action • Restrict allowed hostnames • Rate-limit the actual endpoint • Add abuse detection around sensitive actions CAPTCHA ≠ authorization!!! And a public sitekey ≠ a secret! A small implementation detail, but a pretty important distinction when building abuse-resistant systems!

  • NeriaBasha
    Neria Basha (@NeriaBasha) reported

    N-able says attackers exploiting N-central used Take Control to reach managed endpoints, then registered Cloudflare tunnel services for persistence. If you patched late, N-able says to treat the environment as potentially compromised even when its IOC scan comes back clean.

  • mr_utsav_patel
    Utsav Patel 🇮🇳 (@mr_utsav_patel) reported

    @Cloudflare Same card is working with stripe link for anthropic and I tried with 2 different bank cards and both are getting declined, if possible please add support for UPI for your Indian customers until this issue is resolved

  • srmanuelangel
    Manuel Suarez (@srmanuelangel) reported

    I think infra might be one of the areas where coding agents feel the most unfair. So much of the job used to be babysitting slow feedback loops: change something → deploy → wait 15 min → find out it broke → fix → wait again. Now you can give an agent the Terraform, let it understand how the whole thing is wired together, read the errors, and keep iterating. Obviously this doesn't make infra trivial. Security, WAFs, rate limits, CloudFront, Cloudflare, permissions, etc. still need actual thought. But for relatively simple products, the amount of annoying work that just disappeared is kind of insane. It also makes some infra SaaS feel a lot less essential when you have an agent + a pile of AWS/GCP/Azure startup credits. Much respect to the people who were doing all this **** manually 5 years ago.

  • SW4FlorianM
    Florian M (@SW4FlorianM) reported

    Three findings from the audit of an industrial manufacturer. Fixing all three: about three days of configuration. No code. The site is Webflow behind Cloudflare, and the stack was never the problem.

  • tonyzeoli
    Tony Zeoli (@tonyzeoli) reported

    @RobCairns I run everything through Cloudflare, am hosted at Kinsta, use either Wordfence or Sucuri, and keep everything updated almost daily, so...I don't see the issue. If I were working with shared hosting on GoDaddy with no other security measures, that would be one thing, but I keep things pretty buttoned up. Claude is using the Divi tools - it's just doing the work for me. There's no code, per se. Maybe you should ask before you pass judgment?

Check Current Status