Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 2 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Timikrat (@Timikrat) reported@News_Arena_ @Cloudflare Errors occurring currently
-
SALT 🎸 (@SALTY_ALTY555) reported@aylacroft Imagine the level of encryption @cloudflare could get with a single one of these bad boys.
-
Rob (@RobX402) reported@SwizzyOnChain @Cloudflare That is mine so obviously I cannot give you a biased opinion! $ROB is the centre of my network, utility and x402 agent-to-agent payments.
-
Groktopus (@groktopus) reportedSpoiler: "Cloudflare OS" is NOT an OS. It seems to be trending in AI space to mislabel things as OS's when they are really just another agentic application runtime and workspace. It's still potentially cool (still looking into it). But the "OS" branding leaves a bad taste.
-
KAWS 🐺 (@KawsR310) reported@RobX402 @Cloudflare This **** is a scam it dumped
-
Rob Leathern (@robleathern) reportedQuick analysis here (Ari shared the URL w me, I won’t repeat it), usual disclaimers apply: What it pretends to be. A Luma event page inviting you to Advertising Week New York 2026 — a real conference with real dates (Oct 5–8) at a real venue. The clone is faithful down to the “Report Event” button and a working Google Maps embed, and it hotlinks the actual cover image and favicon from advertisingweek[.]com. The domain, —redacted—— reads as “AdWeek’s event NY” rather than misspelling anything, so string-similarity domain checks won’t flag it. How it works. Clicking “Accept Invitation” opens a pixel-accurate Google sign-in replica with a ten-minute countdown running. Once you submit credentials, you’re parked on a “Validating your credentials…” spinner while your browser quietly polls the attacker’s server once per second. That poll speaks the Telegram Bot API’s getUpdates format — meaning a human operator is sitting in a Telegram chat watching victims arrive, driving each victim’s screen with inline buttons. This is the key distinction: it’s a live relay, not a harvester that stores credentials for later. The operator types your password into the real Google simultaneously and reflects Google’s genuine responses back at you. The command set includes wrongpass and wrongemail, so a typo produces an authentic-feeling retry prompt. TOTP, SMS, email, and WhatsApp codes all get relayed inside their validity windows. Even Google’s number-matching push is defeated — the operator reads the two-digit number off the real prompt and pushes it to your screen, so the number you’re told to tap is correct, and tapping it authorizes their session. What it’s after. Corporate Google Workspace accounts, specifically. The kit hardcodes ~40 consumer email domains — gmail, yahoo, outlook, icloud, proton — and refuses them. Personal accounts are turned away at the door. Pair that with an advertising-industry lure and the target profile is clear: accounts that sit on top of ad budgets, client data, and payment approval chains. The goal isn’t the password; it’s the authenticated session and the persistence that follows — OAuth grants, mail forwarding rules, delegated access. How it avoids detection. Several layers, working together: (a) A fake Cloudflare “Checking if the site connection is secure” screen gates the payload, so automated URL scanners that don’t click never see the phishing content. It also displays invite[.]advertisingweek[.]com as the domain being verified. (b) The JavaScript is obfuscated with an RC4-keyed string array — over 16,000 encoded strings, so grepping the shipped bundle for “password” or “google” returns nothing. (c) CSS class names are randomized per build (toast94, veldt_84), defeating signature-based detection of the cloned layouts. (d) An inline script deletes and freezes React DevTools, specifically blocking inspection of the component state where credentials live pre-submission. (e) The network profile is dominated by genuine Google Maps, Google Fonts, and hotlinked brand images. The only attacker-controlled request is a same-origin POST to a generic /api.php — indistinguishable from ordinary app traffic.
-
Manas Choudhary (@_manaschoudhary) reportedOh man, how come Cloudflare is able to do so many things and knew about these problem statements a year ago????
-
veektor (@0xveektor) reportedWho has been able to login into their @Cloudflare account this morning ? What's all this redirect all about ?
-
tamimbuilds (@tamimbuilds) reportedThe biggest Cloudflare announcement wasn't another CDN feature. They quietly gave AI agents something they've never had before: Their own computer.
-
De UniQue 👑 (@Abdulkarim2) reportedCloudflare wants AI agents to pay $0.001 per API call. A standalone card payment would cost more than the call itself. Its new Monetization Gateway lets a service return an HTTP 402, quote a price, and receive payment before serving the request. At launch, settlement runs on stablecoins over x402. Machine billing already existed, but it ran on accounts, API keys, and invoices piled up over time. What was missing: a way for an unknown agent to pay per request, without the seller onboarding it first. Stablecoins didn't invent machine commerce. They made the smallest transaction worth collecting.
-
riot' (@33xp_) reported@ajrgd @Cloudflare doesn't mean ****. not much you can do with it by pre-reserving plus "cloudflare reserves the right to reject any handle for any reason"
-
Markovian (@MarkovProtocol) reported@CherryJimbo @Cloudflare @CloudflareDev Worth noting what the traces are for today: the operator debugging their own agent. The unbuilt half is traces as evidence — the same spans, hashed somewhere append-only, so a customer or auditor can verify them without trusting the store. The export hook is already there.
-
Al-Yazen (@AlYazen_Wahaibi) reported@MarianaMorales8 @bingersapp Hey there!, Before you start typing your email, please wait for the Cloudflare "Verify you're human" checkbox to appear Once it appears, complete the verification first, then proceed with entering your email. I believe this is a glitch Many people faced the same issue
-
Parth Arora (@heypartharora) reported@BuddhaSource hey Siddharth been following agentic commerce rise since google dropped the agentic-comm protocol and yesterday cloudflare dropped wallets to support around the same use case. An year ago, I was working on AEO/GEO bc i knew this direction was coming, however as an engineer I was quite bad at sales. I’d love to get your mentorship on how should I move ahead now.
-
〽️ᄃムt 🐾 (@mztacat) reported@TweetByWale @Cloudflare Absolutely (that's cloudflae dashboard billing service)