Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 2 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Prmai (@Prmai_) reported@synopsi @Cloudflare been using it for years. never had to pay them a things.
-
Pedro E. Caparrós Torres (@Guelug) reportedCloudflare's CFO just said the quiet part out loud: humans are becoming a "rounding error" in internet traffic. Machine-generated traffic surpassed human traffic in May 2026. Cloudflare had originally predicted this for 2027. They were off by a year. Their new forecast? Within 5 years, bot traffic could be 1000x human traffic. The math is simple. A human shopper visits 5 sites. An AI agent checks 5,000 on their behalf. One prompt, thousands of requests. Now multiply that by every query, every API call, every agent loop. What this actually means: → Analytics are broken. Your "unique visitors" are increasingly agents, not people. Bounce rate, time on page, conversion funnels — all polluted. If you're not filtering bot traffic aggressively, your metrics are lies. → Infrastructure costs shift. CDNs, ISPs, and edge providers are routing more requests for machines than humans. Bandwidth bills scale with agent behavior, not user behavior. → The "internet" is splitting into two: one humans browse, one agents crawl. Different traffic patterns, different latency requirements, different economics. Cloudflare's Seifert framed this as a prediction. It's closer to an observation. The crossover already happened 3 months ago. The question isn't whether agents will dominate internet traffic. They already do. The question is whether the infrastructure we built for humans can handle an internet where humans are noise.
-
Bobby Ivanov (@bnivanovX) reported@Voxyz_ai Is this essentially the cloudflare computer service attached to an agent?
-
Ben Dickson (@bendee983) reportedShower thoughts: The compute shortage will be a lot more insane than we think, and it has much to do with AI security. Recent security incidents with AI models (Claude, GPT, Kimi, etc.) hint at where the industry will be heading. Even if you factor in the marketing and hype and hackmaxxing, the main concern is real: foundation models are becoming increasingly good at breaking into software and IT infrastructure (even when they are not instructed to do so explicitly, as with the OpenAI–Hugging Face incident). As a result, every service provider will want to deploy more security measures at the edges to prevent a potential attack from an AI model. And those additional safeguards will rely on more AI models that can detect attacks and vulnerabilities that would go undetected by heuristics-based systems. Cloudflare will use LLM-based monitoring on every incoming request, Stripe will use LLMs to monitor transactions, every company that has a sizable online platform with many users (social media, blogging, shopping) will want foundation models for security. The demand for compute will go through the roof.
-
INFOSEC.WATCH (@InfosecDotWatch) reportedThe N-central story is bigger than a vulnerable management server. N-able says attackers used the legitimate Take Control feature to reach managed endpoints, then installed a Cloudflare tunnel service for persistence. RMM compromise is a downstream hunt problem.
-
Fagner Sales (@fagnersales25) reported@a_shimanski @Cloudflare I don't have much experience with Cloudflare but I honestly want to give it a shot. I've been locked into Vercel for quite a long (It's so easy to use and setup that I never bothered trying something else)
-
Justin Schroeder (@jpschroeder) reported@dschewchenko Good luck with that. The loop is our fault. Not having limits is 100% a cloudflare problem.
-
Andre Gironda (@AndreGironda) reported@chrissanders88 Initially, sight the incoming IPs from the alert, and associated packetry, e.g., naming resolution. A good lookup service for these IPs is Spur because if a threat actor, likely coming from a vpn or proxy service, and one perhaps unique. If CloudFlare tunnel, check with abuse@
-
güs (@nukefags) reported@NEVER_G0ON Soybooru and ze Jarti haven’t used cloudflare in like 3 years. Null and d0ll swapped it over to a custom DDoS retarding service when the domain was switched to .st
-
Edeb (@_Edeb) reported@Majora__Z @p_e_t_e_r_s_e_n Cloudflare’s Sept 15 change is bigger than it looks. They’re flipping the default: AI training crawlers get blocked on any page that shows ads, and multi-purpose bots like Googlebot (which still does both search indexing and training data collection in one) get caught in the same net unless the site owner manually opts out. That means a huge chunk of the web — especially free-tier and new sites on Cloudflare — could suddenly stop letting Google crawl them. Implications in plain terms: Google’s index starts going blind on large parts of the internet. Search results get thinner, older, and more reliant on whatever they already have cached or on AI summaries that never send traffic back. Publishers finally get real leverage. They can protect their content from being vacuumed up to train models that compete with them, without (in theory) fully disappearing from search — but only if they carefully configure the settings. Most won’t. A lot of smaller sites will just let the default ride and vanish from Google. Users will notice it slowly: more “no good results,” more AI answers that feel hollow, more content locked behind logins or paywalls because free crawling no longer makes economic sense. The open web’s old deal is dying. For thirty years the bargain was “crawl everything for free and send traffic back.” That deal is broken. Cloudflare is forcing the next phase: either separate your crawlers cleanly, pay for access, or get locked out. It’s not the end of the internet. It’s the end of the free-for-all version of it.
-
Davie (@SpartanDavie) reported@rough__sea FYI crypto: Add post-quantum cryptography support where you can please - ML-KEM and ML-DSA. X25519MLKEM768 hybrid is supported in Cloudflare, Safari 26+, Chrome 131+, Firefox 135+ (TLS, no QUIC/HTTP/3), Edge 131+
-
allen (@apgxxn) reportedHe's not even old enough to remember a useEffect took down cloudflare last year
-
Maxxie wei (@xmaxxie1119) reportedGoogle's agent platform went GA with Agent Identity — agents now have credentials, memory, and a browser. Governance just moved from prompts to principals. This week Google took the Gemini Enterprise Agent Platform to general availability with Agent Identity: every agent gets unique, least-privilege credentials, and every operation is logged. The platform is built for long-running agents that keep state for days, backed by a memory bank, plus an Agent Registry — a single source of truth for every agent and tool — and an Agent Gateway for real-time policy enforcement. Agents are no longer stateless prompts. They are principals with credentials, memory, and tenure. The consumer side moved the same week: Gemini Spark now drives desktop Chrome with your logged-in accounts and saved passwords — booking apartment viewings, starting flight bookings — and hands back to a human for payments and sensitive actions, with prompt-injection protection built in. Cloudflare shipped Kitesurf, a browser designed for AI agents. Read the two launches as one statement: the industry is building identity and state for machines the way it built them for employees. The enterprise question is no longer "can the agent do the task?" It is "which agent identity may touch which resource — and what survives when a task spans three days?" That inverts today's default governance, which still treats agents as prompts with permissions bolted on. The platforms are moving to a world where the principal carries the policy: the agent logs in as itself, its credentials are scoped and revocable, its actions are replayable, its memory is inspectable. Monday operator move: give one production agent a real identity this week — a dedicated service account, scoped to the minimum tools, every action logged, stated retention for its state. If the platform cannot do that yet, that is the capability to demand. Identity is the control everything else — policy, audit, revocation, kill switch — hangs on. And scope the job like a micro-need: one role, one metric, one handoff — the agent owns 80% of the loop, with a named human gate for the last 20%. That is what the Micro-Needs method means by choosing the right problem before identity, before memory, before scale. #AgenticAI #EnterpriseAI #AIGovernance
-
Sai Krishna ⚡️ Superblog.ai (@_skris) reportedCan’t really fkn keep up with this company When I moved superblog (v2) from netlify to Hetzner + cloudflare, I implemented caching layer tilting towards hetzner vps because CF’s purge limits were not so great. Recently Claude told me that they give like 5 purges/second for $20/mo and 10/min for free. Seriously? I simply rewrote the caching layer with on-demand purges for superblog’s customers. Essentially the load hitting the hetzner vps is zero until a customer makes any change. Superblog will grow to a large scale even before I pay them anything. They just hate to make money I guess.
-
Artyom Shimanski (@a_shimanski) reported@occupymars___ @Cloudflare all good, ask away. is this cloudflare access you're setting up, or your own login flow?