Traceary

Catalog / Cloudflare Developer Platform

WAF - WAF Release - 2026-08-17

9 days agosecuritychangedOriginal notes

This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640.

Key Findings

  • CVE-2026-65640: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...3590a4adN/AWordpress - Remote Code Execution - CVE:CVE-2026-65640BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Free Ruleset...cfe1a93cN/AWordpress - Remote Code Execution - CVE:CVE-2026-65640BlockN/ARule metadata description refined. Detection unchanged.