跳到主内容
精选85Cloudflare WAF(Changelog)云与平台

Cloudflare WAF 更新:新增 SharePoint RCE 与 Rails 漏洞规则

WAF - WAF Release - 2026-08-04

原文
推荐理由

WAF 用户需关注:新增的 SharePoint RCE 和 Rails 漏洞规则已设为 Block,且 SSRF 云防护默认阻断,建议及时更新托管规则集以抵御这些攻击。

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.

Key Findings

  • CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.
  • CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.
  • Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...052b07cfN/AMicrosoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522LogBlockThis is a new detection.
Cloudflare Managed Ruleset...3a5b40d6N/ARails - Arbitrary File Read & RCE - CVE:CVE-2026-66066BlockBlockThis was labeled as File Upload - RCE.
Cloudflare Managed Ruleset...8242627bN/ASSRF - LocalDisabled-This detection has been removed.
Cloudflare Managed Ruleset...743a63ecN/ASSRF - Local - 2 - BetaDisabled-This detection has been removed.
Cloudflare Managed Ruleset...c2e84e2dN/ASSRF - Cloud - BetaDisabled-This detection has been removed.
Cloudflare Managed Ruleset...ab8af26fN/ASSRF - Cloud - 2 - BetaDisabled-This detection has been removed.
Cloudflare Managed Ruleset...25ba9d7cN/ASSRF - CloudDisabledBlockWe are changing the action for this rule from Disabled to BLOCK
Cloudflare Managed Ruleset...01a076ebN/ASSRF - Local - BetaDisabled-This detection has been removed.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近