Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Ann Arbor, MI | 1 |
| Palermo, Sicily | 1 |
| New York City, NY | 3 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
GP Q (@argosaki) reported🤖 OpenAI and 127 Organizations Warn AI Cyberattacks Are Scaling Fast OpenAI, Anthropic, Google, Microsoft, AWS, Cisco, Cloudflare, CrowdStrike, Visa, Mastercard and dozens of other organizations signed an open letter calling for urgent cyber defense upgrades. ⚫ The warning: AI-powered attacks could become more widespread and more complex in the coming months ⚫ Critical services are at risk, including hospitals, water systems and internet infrastructure ⚫ The letter says current defenses are not enough because of old vulnerabilities, weak access controls, poor patching and technical debt ⚫ Signatories want defenders to get broader access to AI tools, shared fixes, threat data and practical support ⚫ AI model developers are also being asked to fund, train and support under-resourced critical infrastructure teams The bigger signal: AI is now changing both sides of cybersecurity. Attackers get faster, but defenders need the same tools before the gap becomes impossible to close. ⚡ECONOMY NEWS⚡
-
Rue Mohr🇨🇦 (@RueNahcMohr) reported@vccccnv I have never had this issue on a site that did not use cloudflare.
-
Matty (@matankatzzzz) reported@Cloudflare fell 13% in April because Anthropic shipped a cyber model. It’s up 57% since. Turns out AI doesn’t replace the pipes. It floods them. Next big $NET drop won’t come from an AI launch - it’ll come from an outage.
-
Kamil Fabian (@KamilFabian) reported@RueNahcMohr @lmilsfsd @Cloudflare just cler the cache. Problem is at your "receiver" ;)
-
chosem 😖 (@chosem_) reported@synopsi use cloudflare receive and sending. connect receive to an openrouter API, basically most modern AI will do, even cheaper ones. make it categorize: promotion, support, misc. and then route the support to your actual support platform so you can see it all in one place.
-
Alex Casillas (@alexvcasillas) reported@lucataco And then you’ll be ****** up if you live in Spain during the weekends because the ******* ISPs here block Cloudflare entirely because of @LaLiga mafia and their thirst of money, they don’t care to take down entire companies so they can collect their 100€/month subscription for watching football…
-
Larry Diffey (@GrizzledTexan) reported@AEC3DTech Just using Cloudflare is probably good enough. WP Security itself is fine, it's the plugins that cause security issues. But if the site is pretty much static anyway, just don't use WP. There are other headless CMSs that might be more suitable. What are you trying to accomplish with the site?
-
Michiel V. (@mvug) reported@Cloudflare is R2 down? getting errors like AWS HTTP error: ServiceUnavailable (client): Reduce your concurrent request rate for the same object.
-
Tommy Geoco 🇺🇸 (@designertom) reportedcontext: grok bot runs in the cloud out of the box, which is great, but the whole point of registering a computer is letting agents run things on YOUR machine. i have a mac mini as the home base for my whole OpenClaw (and others) agent stack: my Obsidian knowledge vault, my capture scripts, QMD and sub-surface UIs for slices of workflows connected to crons, all of it lives there. grok's agents are supposed to reach into that box and run stuff. the bug: from the iOS app, every one of those commands dies with "couldn't bind the command for review." i checked the mini's side and grok's own exec daemon was connected the whole time but the command never even left the app. same commands run fine from desktop. so it's the mobile approval surface that's broken, not the computer link. and there's no allowlist or auto-approve at all. every command needs a review card that mobile can't show. which means all agent → your-own-computer automation is dead from my phone ended up standing up my own authed relay on the mini + a cloudflare tunnel just to route around the approval layer. it works, but come on. what i want: 1. per-computer command allowlist so trusted scripts skip review 2. fix the review card on mobile 3. when it fails, give the agent a real error instead of a silent retry loop
-
iyda (@notiyda) reported@dean_walsh1 @theo @janaka_a Ah actually cray you just reminded me normal ISP's normally do not have proper peering to IX or cloudflare magic transit either or Lumen or anything proper so most people if you were hosting a game server would have **** ping lmao
-
Chinoman10 (@Chinoman10_) reported@rusabuilds @hieuSSR @Cloudflare Cloudflare sets those up for you in one click when you activate the email sending service on your CF account. Really not an issue.
-
Hieu 🚀 (@hieuSSR) reported@jikkujose @Cloudflare It's not really an issue for me When they're too big, I'll upload it somewhere and send them the link What is your use case? and why is it a big deal to bypass?
-
Disbelief (@bullhooves) reportedHow the 9 fit together in a real stack Think of traffic and trust flowing north–south (user → internet → app) and east–west (workload → workload inside the DC).1. Who is the user? $OKTA authenticates. CRWD and PANW/CyberArk watch for stolen or overly privileged identities. $GEN only matters if the “user” is a consumer, employee family plan, or breach-notification population — not the corporate IdP. 2. How do they get on the network? Three competing Zero Trust overlays: $ZS if you want a pure cloud broker $NET if you already use Cloudflare at the public edge and want SASE on the same backbone $PANW Prisma or FTNT FortiSASE if you want SASE from the same vendor as the NGFW OKTA feeds all four. 3. What carries the packets? $ANET owns the high-performance underlay — especially AI clusters and cloud-scale DCs. It does not replace PANW/FTNT firewalls. The live pattern is Arista fabric + PANW NGFW “inspect once, enforce many.” $FTNT owns the value / branch / OT underlay. $ATEN shows up in service-provider and high-connection-rate DC designs (CGN, Gi/SGi firewall, SSL visibility). 4. What sits in front of the application? Internet-facing: NET first (CDN/WAF/DDoS), sometimes ATEN DDoS/WAF Inside the DC: ATEN ADC/CFW or cloud LB Segmentation: PANW or FTNT NGFW 5. What protects the host and the cloud account? Enterprise: CRWD on the endpoint/workload, PANW Prisma or CRWD in the cloud. Home / small-office / employee devices outside MDM: GEN.6. Who runs the SOC? $CRWD Falcon Next-Gen SIEM if the program is endpoint- and identity-centric PANW Cortex XSIAM if the program is consolidating NGFW + cloud + SOC FTNT FortiSIEM if the fabric is already Fortinet ANET NDR as the network sensor feeding whichever SIEM you picked
-
Zoë (@zoecyber001) reportedRAPID FIRE CYBER NEWS - WEEKEND EDITION The weekend wasn't quiet. 1. Manchester Airports Group is facing an alleged data theft. Extortion group FulcrumSec claims it stole around 86 GB of data containing customer, booking and travel information. 2. Berlin's government is refusing to pay ransomware attackers who claim to have stolen 5.79 TB of data from its network. The city confirmed the extortion attempt but says it won't pay. 3. Several Chrome and Edge extensions were caught delivering malware that can steal crypto-related information, browser history and sensitive data. Some were also used to inject fake ClickFix prompts. 4. Infostealer malware is now stealing active Claude sessions. Anthropic warned that attackers can potentially take over Claude accounts using stolen session information without simply needing the user's password. 5. Microsoft uncovered TerminalFix, a new ClickFix campaign using fake Cloudflare CAPTCHA pages to trick people into running malicious commands that install a reverse-tunnel backdoor. Cybersecurity keeps finding new ways to abuse things we already trust.
-
DONK • ᚐᚒᚄᚈᚔᚅ • 🇮🇪🇵🇸 • 🧡🤍🩷 (@RaraCool04) reported@MDoyler @VodafoneIreland To fix, log into your router using the instructions at the back or bottom of the router, go to Internet > DNS, choose manual and use 1.1.1.1 as the primary and 8.8.8.8 as the secondary. These are DNS providers by Cloudflare and Google, not Vodafone, and are currently working.