Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

Cloudflare One Client for Windows (version 2026.8.2100.0)

View as MarkdownAgent setup

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release includes the following highlights:

  • Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across tunnel reconnections.
  • Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved connection reliability on devices with very large hosts files. The client now detects a large hosts file, allows more time for its initial DNS check, and shows a banner letting the user know that connecting may take longer.
  • Faster tunnel reconnections and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.
  • A service recovery mechanism, backed by a Windows scheduled task, now starts the client service on system unlock if it is not already running. This is enabled by default.

Additional changes and improvements

  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Individual DNS-over-HTTPS queries now time out instead of hanging when the upstream server stops responding.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • Added an MDM setting to prefer IPv4 when resolving hostnames in proxy mode. The setting is off by default.
  • The client no longer requires the Windows WLAN AutoConfig service to be running.
  • Fixed the client reconnecting while Emergency Disconnect was active after switching organizations or re-registering.
  • Fixed the client being unable to connect after an upgrade when its stored registration credentials no longer matched its configuration.
  • Fixed the client service restarting unexpectedly when it was slow to respond, such as after waking from sleep.
  • Fixed the client service failing to restart after an unexpected termination.
  • Fixed the client UI getting stuck in a connecting state after sleep and wake even though the tunnel was connected.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
  • Fixed the client continuing to report “No network” after a successful manual disconnect.
  • Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation.
  • Fixed latency spikes and traffic interruptions during TPM-backed API authentication when hardware-backed registration is enabled.
  • Fixed trailing whitespace in BIOS serial numbers causing serial-number and client-certificate device posture checks to fail.
  • Fixed the client UI crashing at startup when it could not write to the Windows registry.
  • Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
  • Fixed a startup crash when date formatting data for the system locale had not yet loaded.

Known issues

  • A Windows DNS client regression may cause connectivity check failures on systems containing large hosts files. While this release includes a fix to mitigate this issue, users may still experience reduced DNS performance and connectivity check failures.