Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cloudflare Down – 6 Hour of Massive Global Service Outage Cause Customers Unreachable From the Internet

## Incident Report: Cloudflare BYOIP Service Outage

Incident Report: Cloudflare BYOIP Service Outage

Cloudflare encountered a significant global service disruption on February 20, 2026, affecting customers using the Bring Your Own IP (BYOIP) services. The outage lasted for six hours and seven minutes, beginning at 17:48 UTC, and resulted in the unintentional withdrawal of customer BGP routes, making numerous services and applications inaccessible.

The disruption was due to an internal configuration update, not a cyberattack. It impacted 25% of all global BYOIP prefixes, causing HTTP 403 errors on the 1.1.1.1 public recursive DNS resolver website.

Technical Breakdown of the Addressing API Failure

The root cause was traced to a bug in Cloudflare's Addressing API, introduced during an automated cleanup task. This task was part of Cloudflare's "Code Orange: Fail Small" resilience initiative and was intended to replace manual removal processes for BYOIP prefixes. A system deployed to periodically remove pending objects mistakenly executed an API query with an unassigned pending_delete flag, causing the deletion of approximately 1,100 BYOIP prefixes and their dependent service bindings.

As a result, affected connections entered a state known as BGP Path Hunting , where connections continuously search for routes until they fail. The impact extended across multiple core products:

Cloudflare encountered a significant global service disruption on February 20, 2026, affecting customers using the Bring Your Own IP (BYOIP) services.
Peter Collins · Thehackingpost

Core CDN and Security Services: Traffic routing failures led to connection timeouts. Spectrum: Traffic proxying for applications failed completely. Dedicated Egress: Outbound traffic could not reach destinations. Magic Transit: Complete connection failures and timeouts were experienced.

Recovery Efforts and Planned Remediation

Recovery was delayed due to varied impacts on customer prefixes, requiring intensive data recovery operations. Some users self-remedied by toggling advertisements via the Cloudflare dashboard, while others required manual restoration of service bindings. Engineers had to update global configurations across the edge network to restore affected accounts.

To prevent future incidents, Cloudflare is accelerating several critical architectural changes under its Code Orange mandate. This includes standardizing the API schema to prevent flag interpretation errors, implementing circuit breakers for rapid BGP prefix deletions, and establishing operational state snapshots to isolate customer configurations from production rollouts.

Advertisement

Cloudflare concluded its incident report with an apology, acknowledging the outage's impact on its commitment to a resilient network.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories