Skip to content

Commit 1c502d1

Browse files
authored
WAF Release 26 Sep (#25456)
1 parent f026e4e commit 1c502d1

File tree

1 file changed

+148
-0
lines changed

1 file changed

+148
-0
lines changed
Lines changed: 148 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,148 @@
1+
---
2+
title: "WAF Release - 2025-09-26"
3+
description: Cloudflare WAF managed rulesets 2025-09-26 release
4+
date: 2025-09-26
5+
---
6+
7+
import { RuleID } from "~/components";
8+
9+
**Managed Ruleset Updated**
10+
11+
This update introduces 11 new detections in the Cloudflare Managed Ruleset (all currently set to Disabled mode to preserve remediation logic and allow quick activation if needed). The rules cover a broad spectrum of threats - SQL injection techniques, command and code injection, information disclosure of common files, URL anomalies, and cross-site scripting.
12+
13+
<table style="width: 100%">
14+
<thead>
15+
<tr>
16+
<th>Ruleset</th>
17+
<th>Rule ID</th>
18+
<th>Legacy Rule ID</th>
19+
<th>Description</th>
20+
<th>Previous Action</th>
21+
<th>New Action</th>
22+
<th>Comments</th>
23+
</tr>
24+
</thead>
25+
<tbody>
26+
<tr>
27+
<td>Cloudflare Managed Ruleset</td>
28+
<td>
29+
<RuleID id="3ffd242b4ba242ca965022d3a67d8561" />
30+
</td>
31+
<td>100859A</td>
32+
<td>SQLi - UNION - 3</td>
33+
<td>N/A</td>
34+
<td>Disabled</td>
35+
<td>This is a New Detection</td>
36+
</tr>
37+
<tr>
38+
<td>Cloudflare Managed Ruleset</td>
39+
<td>
40+
<RuleID id="91d9cf56355b4ab88481b2fd4de80468" />
41+
</td>
42+
<td>100889</td>
43+
<td>Command Injection - Generic 9</td>
44+
<td>N/A</td>
45+
<td>Disabled</td>
46+
<td>This is a New Detection</td>
47+
</tr>
48+
<tr>
49+
<td>Cloudflare Managed Ruleset</td>
50+
<td>
51+
<RuleID id="c15ca8e8290f485287037665f2be3ddf" />
52+
</td>
53+
<td>100890</td>
54+
<td>Information Disclosure - Common Files - 2</td>
55+
<td>N/A</td>
56+
<td>Disabled</td>
57+
<td>This is a New Detection</td>
58+
</tr>
59+
<tr>
60+
<td>Cloudflare Managed Ruleset</td>
61+
<td>
62+
<RuleID id="56669615f2984c2cac8c608980a252a8" />
63+
</td>
64+
<td>100891</td>
65+
<td>Anomaly:URL - Relative Paths</td>
66+
<td>N/A</td>
67+
<td>Disabled</td>
68+
<td>This is a New Detection</td>
69+
</tr>
70+
<tr>
71+
<td>Cloudflare Managed Ruleset</td>
72+
<td>
73+
<RuleID id="c41789fb6370431d809567d17e7d3865" />
74+
</td>
75+
<td>100894</td>
76+
<td>XSS - Inline Function</td>
77+
<td>N/A</td>
78+
<td>Disabled</td>
79+
<td>This is a New Detection</td>
80+
</tr>
81+
<tr>
82+
<td>Cloudflare Managed Ruleset</td>
83+
<td>
84+
<RuleID id="b995d0b930604fa6b8d9b2a13792565c" />
85+
</td>
86+
<td>100895</td>
87+
<td>XSS - DOM</td>
88+
<td>N/A</td>
89+
<td>Disabled</td>
90+
<td>This is a New Detection</td>
91+
</tr>
92+
<tr>
93+
<td>Cloudflare Managed Ruleset</td>
94+
<td>
95+
<RuleID id="ab8277e3f432400bbd9403dd42978e38" />
96+
</td>
97+
<td>100896</td>
98+
<td>SQLi - MSSQL Length Enumeration</td>
99+
<td>N/A</td>
100+
<td>Disabled</td>
101+
<td>This is a New Detection</td>
102+
</tr>
103+
<tr>
104+
<td>Cloudflare Managed Ruleset</td>
105+
<td>
106+
<RuleID id="3ec33bc5ac77495a9f55020e3ab43f7e" />
107+
</td>
108+
<td>100897</td>
109+
<td>Generic Rules - Code Injection - 3</td>
110+
<td>N/A</td>
111+
<td>Disabled</td>
112+
<td>This is a New Detection</td>
113+
</tr>
114+
<tr>
115+
<td>Cloudflare Managed Ruleset</td>
116+
<td>
117+
<RuleID id="4375dc90c7af4c55908f6b95c1686741" />
118+
</td>
119+
<td>100898</td>
120+
<td>SQLi - Evasion</td>
121+
<td>N/A</td>
122+
<td>Disabled</td>
123+
<td>This is a New Detection</td>
124+
</tr>
125+
<tr>
126+
<td>Cloudflare Managed Ruleset</td>
127+
<td>
128+
<RuleID id="945c5aa9f45141dd872d7ec920999be0" />
129+
</td>
130+
<td>100899</td>
131+
<td>SQLi - Probing 2</td>
132+
<td>N/A</td>
133+
<td>Disabled</td>
134+
<td>This is a New Detection</td>
135+
</tr>
136+
<tr>
137+
<td>Cloudflare Managed Ruleset</td>
138+
<td>
139+
<RuleID id="2c20b5e8684043f48620ff77b4026c88" />
140+
</td>
141+
<td>100900</td>
142+
<td>SQLi - Probing</td>
143+
<td>N/A</td>
144+
<td>Disabled</td>
145+
<td>This is a New Detection</td>
146+
</tr>
147+
</tbody>
148+
</table>

0 commit comments

Comments
 (0)