Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Paris, Île-de-France | 2 |
| New York City, NY | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
| Noida, UP | 2 |
| Jewar, UP | 1 |
| Braga, Braga | 1 |
| Prievidza, Nitriansky | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
DFIR Radar (@DFIR_Radar) reportedAiTM phishing campaign hits universities, EU and UN agencies using compromised aged domains, rotating PhaaS kits, and procurement lures to steal MFA-protected sessions in real time. Key details: - Attack chain: phishing emails sent from compromised Outlook accounts use RFI and bid-invitation lures, directing victims through fake document portals (testserveren[.]com, barifurniture[.]net), Cloudflare Turnstile or actor-hosted CAPTCHA, then cloned Microsoft login pages impersonating targets like the European Investment Bank. Email addresses are embedded in URL paths to personalize the illusion. - The actor rotates three PhaaS kits: EvilProxy (reverse proxy, active since 2022), FlowerStorm/Storm-1167 (likely Rockstar2FA rebrand, reverse proxy targeting M365), and Kali365 (device code abuse plus AiTM session capture, first seen April 2026). RDGA patterns distinguish the kits: FlowerStorm uses corporate-buzzword .de domains; EvilProxy uses corporate-buzzword .net/.com. - Infrastructure fingerprint: compromised aged domains averaging 6-plus years old, injected with an index.php to serve phishing content. No ownership change indicators. RDGA domains include usersatisfactionlab[.]de and q1evaluationperformance[.]net. - MFA is not a defense here. Session cookies and tokens are intercepted in real time as victims complete legitimate MFA flows, giving the actor an authenticated session without ever cracking a code. #DFIR_Radar
-
MD Fazal Mustafa (@the_mdfazal) reported@MohapatraHemant My stack cost $0. All the code is in GitHub, cdn, and deployed at Cloudflare. Never crossed the free limit.
-
Mehmet Yildiz (@albursavi) reported@RyanEls4 Cloudflare... Also real time payload can be 'cached' based on data change interval through their database rather than KV service depending on it's importance.
-
Anthony Thorne (@AnthonyThorneCG) reported@RyLiberty Is your site down? Was going to order a poster, getting a cloudflare message.
-
Chris (@burnerDevAcct) reported@jackfriks the obvious answer is lovable/bolt/replit and supabase (yes, i know about the supabase issues). cloudflare and 3rd party db signups are too much for someone just starting - and any of the desktop apps she will be in permission hell (ie clicking "always allow" 400 times).
-
Michael @ Upstack Data (@michael_upstack) reportedSoftware is a lot more like building a house. An architect decides where the walls go, where the plumbing runs, where the electrical lines run. Then specs how thick the walls need to be to hold the roof. What happens if a hurricane comes through? Is the foundation high enough for a flood? Same exact questions. Just asked about a building instead of a system. A software engineer answers the same category of questions. What happens if the internet goes down? What happens if Cloudflare has an outage? What happens if traffic spikes overnight? You can't put lights in the ceiling before the walls go up. And you can't put buttons on a screen before the API that supports them exists.
-
Hunter Guo (@hunterguo101) reportedCodex 5.6 Sol has crossed a line that Fable has not: it can own a production outcome, not just generate convincing code. I reached that conclusion after two real jobs this week. First, I needed to integrate our 1toAll content agent into 11agents and deploy it. The job crossed two repositories, isolated workspaces, authentication, persistent production data, Cloudflare, and release automation. I spent an evening working through it with Claude. Each answer looked locally reasonable, but the system never became usable. One fix exposed another gap. A deployment appeared successful while the server was still running an older release. Sol inherited the shared memory and reconstructed the state itself. It traced ownership across both repos, fixed workspace isolation and login, added tests, deployed, then watched production until the running release SHA matched the new commit. The second job was the Flatkey website. Fable had produced a polished surface, but search, model switching, language switching, signup routes, API details, pricing and several buttons were incomplete or stale. Sol received one goal: make the site safe to ship. It checked the real product and docs, repaired the interactions and facts, deployed to a canary, ran 20 interaction tests and 12 production-path checks, then shifted traffic with a rollback path ready. Flatkey was part of the actual workflow here, not a decorative product mention: the model-routing infrastructure and its public surface had to agree in production. Code generation is now the minimum bar. The useful distinction is whether an agent can recover context, keep moving through newly discovered problems, verify the real system, deploy safely, and confirm the final state. Fable is still a strong generator. In long-running production work, Sol behaves more like an accountable engineering unit. That changes the org chart. Humans can concentrate judgment at a few gates: why this matters, what “done” means, and which boundaries cannot be crossed. The agent can own the path between them.
-
Katewerk (@katewerk) reported@helloitsoctocat Cloudflare can't even figure out how to add a "close account" option on their user dashboard. Suspend your subscription? You'll be automatically charged and good luck deleting your cc from billing, becuase billing has no dedicated support. Then the AI slop bot provides instructions based on pages that no longer exist. The least competent tech service I've ever encountered.
-
clara (@declarative_) reported@HSVSphere but also this way of doing it leads to accesses to websites behind cloudflare being hidden from internet providers even when they can look at the ip, so who's to say it's good or bad
-
Ethan Walker (@maria6186551590) reportedFollow me and I’ll help you cut through market noise and find stocks with strong growth potential. $NOW — ServiceNow — Buy at $92-$98 $SNOW — Snowflake — Buy at $246-$255 $DDOG — Datadog — Buy at $237-$245 $NET — Cloudflare — Buy at $253-$263 $ZS — Zscaler — Buy at $137-$142 $VEEV — Veeva Systems — Buy at $178-$185 $SAP — SAP — Buy at $145-$151 $CRM — Salesforce — Buy at $153-$162
-
Raj Sitaula (@raj_sitaula) reportedFalse reports should not be enough to label a legitimate website as phishing without a proper review. We hope Cloudflare investigates this issue fairly and restores access as soon as possible. @Cloudflare @CloudflareHelp
-
Adam (@_overment) reportedwas thinking about that too. Webflow, Framer, Make, Airtable, all gone. and there are memes about AI replacing $500 of software with $5000 in token bills. but in this case it's more like "the way I work has changed". now Cloudflare for example is what I need. and I don't need builders, classic CMS, or visual workflow editors anymore. agents handle all of it faster and more comfortably. I love not having to manually format the damn markdown when publishing a blog post.
-
Elion's Pops ⌨️🚀💰 (@EseDevlin) reported@uche_ui vercel hosted abi? blocked on Glo network. You should route it through cloudflare to circumvent the problem
-
EmoPorEmilio 🇺🇾 (@emoporemilio_en) reported@threepointone at this point I just let codex and claude code use the cloudflare ai setup and don't bother with much, I haven't gotten even 1 problem yet
-
Thomas Schulz (@thomasschulzz) reported@danielbelfort @jacobmparis honestly the primary reason i pay for vercel. i know they got me covered. all these people talk about cheaper prices on cloudflare and whatever, but u dont get this kind of support. i'm in an early testing group for their product eve and they send PRs to fix issues immediately