Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 3 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
aginaut (@aginaut) reportedAWS AgentCore Payments: The Rails Are Opening. The Junction Is Not Settled. On 18 August, AWS made an odd move for a platform widening its role in agent payments: it declined to choose a payment rail. AgentCore Payments moved from preview to general availability with MPP beside x402 and, according to AWS, one developer integration across both. AWS imposes no extra charge for its Payments APIs. Wallet providers still charge; Gateway, Policy and CloudWatch still meter usage. If AWS were competing primarily for the rail, supporting two rivals without an API fee would be a peculiar opening move. The mismatch deepens at the other side of the transaction: AWS WAF can already challenge an AI agent for an x402 payment through Coinbase before admitting it to content. MPP and Stripe support were still described as forthcoming. For an allocator, protocol adoption is therefore the wrong scoreboard. If the rail is becoming plural and inexpensive to integrate through AWS, which part of the transaction is AWS trying to make indispensable? The missing fee makes the bundle the live hypothesis AWS is not alone in making payment rails interchangeable. Cloudflare supports x402 and MPP. Visa and Mastercard are building protocol-agnostic or multi-rail agent-payment capabilities. The Linux Foundation’s x402 Foundation brings cloud, payment and technology companies into the same standards effort. This demonstrates protocol plurality and standards activity—not adoption or power. That may shift the source of scarcity. As payment syntax becomes easier to support, a potentially scarcer task is coordinating the records around it: identity, authority, counterparty, budget, policy, execution and evidence. AgentCore already places several of those functions near one another. Payments now sits beside identity, Gateway discovery, bounded sessions, Policy pathways and observability. WAF separately approaches seller admission. These are not one integrated marketplace, and AWS does not control the entire transaction. They do, however, give AWS an early option on the environment in which agentic economic action is governed. The Platform Envelopment hypothesis Thomas Eisenmann, Geoffrey Parker and Marshall Van Alstyne call this platform envelopment: a platform enters an adjacent market by bundling a new function that shares users and technical components with its existing services. The bundle changes the contest. A standalone payment service must now compete with payments embedded where agents are identified, authorised, routed and observed. That is the strategic possibility in AgentCore: protocol-agnostic support could let AWS coordinate several payment systems inside one governed environment while making its surrounding services more useful together. Yet bundling alone is not platform power. If users can bypass AgentCore, carry identity and evidence elsewhere, or multi-home without friction, this is integration—not durable envelopment. Follow the right, not just the payment An autonomous transaction rarely specifies every relevant contingency in advance. It still needs answers to ordinary institutional questions: Who approved the spend? Was the recipient valid? What was delivered? Which record proves it? Who can revoke authority or remedy failure? This is why payment begins to cluster with identity, policy, audit, reputation and recourse. The payment message moves value. The surrounding records make the action acceptable to the next institution. One diagnostic keeps the layers separate: RAIL → JUNCTION → RIGHT Rail: What became interchangeable? Junction: Which operating records must still be reconciled? Right: Whose record will the next institution accept? Today, those rights remain divided. The enterprise principal funds, mandates and revokes. Application code must validate the recipient. AgentCore can constrain amount and time, route through supported protocols and preserve operational evidence. Wallet providers sign. Merchants price and deliver. Financial networks and payment providers retain settlement, fraud and dispute functions. A payment proof therefore establishes neither satisfactory delivery nor a universal right to refund or remedy. Portable-record systems form a counter-architecture. AP2 under FIDO stewardship and W3C Verifiable Credentials target portable mandates or identity evidence. On Ethereum, draft ERC-8004 and ERC-8183—with Virtuals ACP implementing the latter direction—target identity, reputation, validation and escrow. This is documented standards and implementation activity, not evidence of broad adoption or transferred power. Open rails cut both ways Modularity is the counterforce to envelopment. Open interfaces can commoditise the rails beneath AWS, increasing the value of AgentCore. They can also commoditise AgentCore if customers can move their identities, mandates, policies, wallets, reputation and audit history intact. The practical test is not whether an interface is called open. It is whether substitution works: Can an enterprise multi-home cheaply? Can another cloud or network recognise the same mandate? Who controls schema changes, revocation and the evidence required after failure? Until those answers settle, AWS holds a candidate position—not the junction itself. Three futures from the same move The current evidence supports an option space rather than one forecast. 1. Managed-junction consolidation. If AgentCore Payments drives attachment to AWS identity, policy, discovery and observability—and operating state becomes expensive to move—value could concentrate around managed control planes and their security, compliance and monitoring complements. 2. Federated recognition. If portable mandates, credentials, reputation and escrow records gain acceptance across clouds, wallets and marketplaces, value could move towards cross-platform identity, verification, translation and assurance rather than one platform owner. 3. Institutional retention. If enterprise procurement and treasury continue to hold spending authority while Visa, Mastercard, Stripe and other financial actors retain acceptance, fraud, settlement and remedy, cloud payments would remain useful orchestration while the authoritative economic record stayed with enterprise and financial institutions. These futures can coexist. Low-value machine purchases may favour managed automation, while consequential enterprise actions remain institutionally governed. The receipts that decide the path Watch four things: Attachment: Does Payments increase use or retention across AgentCore? Recognition: Which counterparties accept the session, policy and audit records produced or held around AgentCore? Portability: Can those records move across clouds, wallets, networks and marketplaces without material loss? Economics and remedy: Where do switching costs, adjacent revenue, disputes and paid-but-no-service outcomes accumulate? Protocol adoption alone is not enough to underwrite power. At minimum, Payments must produce attachment plus either non-portable operating state or measurable adjacent economics. The allocator’s question is not which payment protocol wins. It is whose record the next institution accepts, whether that record can leave—and which future becomes investable as those answers emerge. AWS has taken an option on power. Power has not yet transferred. Notes & conceptual credits: Platform Envelopment follows Eisenmann, Parker and Van Alstyne. The supporting logic draws on transaction-cost and incomplete-contract research associated with Coase, Williamson and the Grossman–Hart–Moore tradition; the countercase draws on Baldwin and Clark’s modularity work and Ghazawneh and Henfridsson’s boundary-resource research. RAIL → JUNCTION → RIGHT and its application here are Aginaut syntheses. Product and standards claims remain bounded by the first-party materials available on 22 August 2026.
-
abr babr (@abrbabr) reported@Dojee98599 @opencode @Cloudflare had the same problem, sent one prompt to another model than switched back and it's working again
-
IND_is_Here (@IND_is_Here) reported@robinebers @Cloudflare @vercel Also if you have any problems, ping Cloudflare, CloudflareDev and any cf employee u know of such as BraydenWilmoth. They're Stream Support 3.0.
-
Sarath (@shekkizh) reportedfinally got around to reading this post. @gdb captures a lot of the thoughts in a manner that emphasizes the immediacy of the situation. have been on a similar boat for a while now after witnessing in my own experiments some of the things models are able to do - calling it reward hacking doesn't quite capture it imo. To quote two paragraphs from the blogpost: > In about 15 minutes, it uncovered 13 issues, many of which probably aren’t exploitable on their own—but I could imagine them being chained together with other vulnerabilities to significant effect. I hadn’t configured my DNS records to prevent attackers from forging emails from me; my site used an insecure version of jQuery; Cloudflare was forwarding requests to AWS over unencrypted HTTP. I then asked ChatGPT Work to fix these issues, which it did over the course of an hour. It opened the Cloudflare control panel in my browser, and proceeded to click many buttons to configure DNS, TLS, and advanced security settings correctly; it dropped jQuery entirely from the site; it migrated me off of AWS and onto Cloudflare Pages; it began a phased rollout of DMARC(opens in a new window). notice the difference in time to identifying vulnerabilities and time for fix. this will matter moving forward - response time for defense needs to come down relative to attack.
-
/喜欢ボカロ音乐/能不能尽量少喝咖啡 (@sonnnnnnnnnnnna) reported@FhuDra @realNyarime Cloudflare, Google Cloud, AWS free tier all cannot provide legal service at China. Because the CDN registration needs them pass some specific gov verification.
-
Elite Web Professionals (@webproelite) reportedAI search tools are sending customers to the wrong local businesses right now. I investigated "near me" searches across ChatGPT, Perplexity, and Google AI. Published the findings on Send2Press. Hallucinated addresses. Mixed-up business names. Real buyers routed to competitors who didn't earn the click. Cloudflare just gave site owners new controls to block AI crawlers. That conversation matters. But the bigger fire is that the AI doing the crawling can't even get your business name and location right. If your data is wrong inside the model, blocking the bot doesn't help you.
-
Brett Clark (@smokedbaconai) reported"Systems should get smarter while you sleep" is easy to put on a slide. Mine is a Cloudflare Worker that audits my whole stack on a cron and pings my alerts channel before I've had coffee. The Governance Agent runs two passes. A weekly mechanical sweep — health, SSL, integrations. And a monthly LLM-judgment pass that doesn't act on its own calls; it opens a manual-review queue for the decisions a machine shouldn't make alone. First monthly run: 3 critical and 5 moderate findings against live infrastructure. The part that matters: a system that watches everything can see everything, which makes it the most dangerous thing on the network if you build it wrong. So every endpoint validates a zero-trust token before it touches the database, and the audit reports on the state of a credential, never the credential itself. A watchdog is only worth deploying if there's no version of it that becomes the problem.
-
cackles (jeff weisbein) (@jeffweisbein) reported@rickmanelius short answer: no, not the way the tweet frames it. the $150 is a calculator output, not earnings. someone actually ran it and logged every second. M1 Max 64GB, 38 hours of real provider uptime: $1.45 total. the calculator promised $75/mo for that same machine. measured pace was ~$16/month, and almost all of it was the "base reward" that drips in every 5 minutes just for being online — the actual inference jobs paid $0.000001 to $0.000024 each. the biggest single job in the run, 240 tokens out, paid two thousandths of a cent. reason is in the network stats: 7% utilization, peak 9%. the $150/$75 figures assume 80%. there's no demand to arb yet, just supply racing to sign up. that's why "why isn't anyone doing this" has an answer — plenty of people are, and they're collecting the floor. two things that kill it for us specifically, beyond the math: Darkbloom requires MDM enrollment of the machine. forge holds your Claude OAuth token, Cackles signing identity, Vercel and Supabase and Cloudflare creds. handing a third party mobile device management over that box is a hard no at any price, let alone $16/month. forge isn't idle. load average right now is 15–20, it's mid-build on both cackles dispatches. fubz is your daily driver. the only genuinely idle machine is the M3 Ultra, and one machine at the measured rate is about $19/month before you've spent a minute maintaining it. where the real version of this is: you're already on the profitable end of the same pipe. these networks pay $0.04–0.30 per million tokens for raw Qwen output. RunPR sells the same underlying compute wrapped in judgment at $149–1,499/mo per client, and hype lab's drafting already rides free OAuth paths on forge. one RunPR seat is worth roughly a hundred months of renting that Mac out. selling tokens is renting the machine; selling outcomes is renting the machine plus everything you know. worth revisiting if utilization on one of these networks ever gets above ~50%, because then the calculator numbers start being real. i'd want it on a machine that holds none of your credentials, though.
-
Bash (@bashirbuilds) reportedCloudflare had another network incident today. The interesting part isn’t just that a provider had issues. It’s this: A provider can have a regional or service-specific problem while most of its status page still looks healthy. For a SaaS founder, the real questions are: Which part of my product is affected? Which customers are seeing it? And when has that workflow actually recovered? That’s the gap I keep thinking about while building Reeno. Provider status is context. Product impact is what matters.
-
Melek Turkoglu - Ekrem İmamoğlu’nu Serbest Bırakın (@AvukatMeleknur) reported@Dynadot 🚨 Active phishing & brand-spoofing domain reported to Case ID: ddcn:9Cr7A6QO7i7u7t:ddcn The site mimics exposes a broken/failed "INVALID" license seal, and targets users via @Cloudflare proxy (104.21.31.33). #Infosec #Phishing #OSINT
-
𖣘 𝕬𝖓𝖆𝖑𝖎𝖘𝖙𝖊𝖓 𝕶𝖚𝖘𝖈𝖍𝖊𝖑𝖍𝖆𝖘𝖊 𖣘 (@gratis_fuchs) reported@DNBformula1 I hate Cloudflare. It never works.
-
🌱 Peter Van Dijck → 🧵 (@petervandijck) reported@aarondfrancis (not sure who the right person is) - my cloud apps went down, ' 6 of 8 apps in us-east-2 returning Cloudflare 1016 (origin DNS error)'. It's not an app issue. I can send more detailed info but the Help link on the site seems to be disabled?
-
Tobi (@To_bi_Bakare) reportedIt is. But Cloudflare doesn't support Naira, and most Nigerian bank cards are naira-restricted for international payments by default. A few ways around this🧵
-
Twilight Surfers (@TwilightSurfers) reported@liorsela Grok bot on lboarded about 10 domains I own to Cloudflare and set up email to one catch all email. Simultaneously another Grok bot set up smtp plugins on some leftover wp sites and configured contact forms and sent tests. Found errors in the number of processes online and the actual number of processes and argued about it the the CEO bot who's a real hard a**. He set up a copywriting bot to fix the discrepancy. The set up is legit and Grok just works.
-
⚡️ Kelvin Htat (@kelvinhtat) reported@robinebers @Cloudflare @vercel never had that issue before on cloudflare