Cloudflare One Client for Windows (version 2026.8.2100.0)
A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.
This release includes the following highlights:
- Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across tunnel reconnections.
- Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
- Improved connection reliability on devices with very large hosts files. The client now detects a large hosts file, allows more time for its initial DNS check, and shows a banner letting the user know that connecting may take longer.
- Faster tunnel reconnections and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.
- A service recovery mechanism, backed by a Windows scheduled task, now starts the client service on system unlock if it is not already running. This is enabled by default.
Additional changes and improvements
- Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
- Improved client reaction to the current network lowering its MTU.
- Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
- Individual DNS-over-HTTPS queries now time out instead of hanging when the upstream server stops responding.
- Improved API reliability by retrying requests dropped when reusing pooled connections.
- Added an MDM setting to prefer IPv4 when resolving hostnames in proxy mode. The setting is off by default.
- The client no longer requires the Windows WLAN AutoConfig service to be running.
- Fixed the client reconnecting while Emergency Disconnect was active after switching organizations or re-registering.
- Fixed the client being unable to connect after an upgrade when its stored registration credentials no longer matched its configuration.
- Fixed the client service restarting unexpectedly when it was slow to respond, such as after waking from sleep.
- Fixed the client service failing to restart after an unexpected termination.
- Fixed the client UI getting stuck in a connecting state after sleep and wake even though the tunnel was connected.
- Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
- Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
- Fixed the client continuing to report “No network” after a successful manual disconnect.
- Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation.
- Fixed latency spikes and traffic interruptions during TPM-backed API authentication when hardware-backed registration is enabled.
- Fixed trailing whitespace in BIOS serial numbers causing serial-number and client-certificate device posture checks to fail.
- Fixed the client UI crashing at startup when it could not write to the Windows registry.
- Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
- Fixed a startup crash when date formatting data for the system locale had not yet loaded.
Known issues
- A Windows DNS client regression may cause connectivity check failures on systems containing large hosts files. While this release includes a fix to mitigate this issue, users may still experience reduced DNS performance and connectivity check failures.