Cloudflare experienced a significant outage that caused widespread 500 Internal Server Errors across numerous major websites, including LinkedIn, Zoom, Canva, and X. The disruption was traced to a change in Cloudflare's web application firewall (WAF), which was updated to mitigate a newly disclosed industrywide vulnerability in React Server Components. The outage also impacted Cloudflare's own dashboard and APIs, with users and service trackers like DownDetector reporting thousands of connection issues. Cloudflare confirmed that the incident was not the result of a cyberattack but rather an internal deployment intended to enhance security against potential exploitation of the React flaw.
The outage, which began around 8:47 GMT, was quickly investigated and a fix was implemented, allowing affected services to come back online. This event underscores the risks associated with rapid security mitigations in complex, widely used infrastructure, as even well-intentioned updates can inadvertently disrupt global internet services. Cloudflare noted that this was the second outage in a month, though the causes were unrelated, highlighting the challenges faced by major service providers in balancing security and availability.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
After the disruption, Cloudflare confirmed the outage was caused by the WAF deployment made to address the React Server Components vulnerability and stated it was not the result of a cyberattack. This clarified the cause of the incident and distinguished it from malicious activity.
Early on December 5, 2025, Cloudflare suffered a brief outage that caused 500 Internal Server Errors and disrupted access to major websites including X, LinkedIn, Zoom, and Canva. Services were restored quickly after the incident.
Cloudflare deployed a web application firewall change intended to mitigate a newly disclosed industrywide vulnerability affecting React Server Components. The change was an internal security response rather than a reaction to a cyberattack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.