Cloudflare's Cloud Access Security Broker (CASB) had degraded availability for 39 minutes on 26 September 2026. The fault sat in Cloudflare's own CASB and policy-sharing systems, not in anything you run.
Started
10:20 UTC
Duration
Lasted 39m
Source
IsDown
Next time
Cloudflare is degraded. Is your product working?
An incident on their side does not always mean an outage on yours, and the only way to know is to already be watching your own endpoints. Set that up in under a minute and you will be notified the next time your own site is affected. And there will be a next time.
50 monitors for your own websites. No card.
Affected components: Cloudflare Sites and Services, Cloud Access Security Broker (CASB)
What happened?
Cloudflare logged one incident on this day, starting at 10:20 UTC and lasting 39 minutes. It affected two listed components: Cloudflare Sites and Services, and the Cloud Access Security Broker (CASB). Cloudflare's first update said it was investigating degraded availability impacting CASB and policy sharing between accounts in Cloudflare Organizations. The same update warned that CASB findings might be delayed, and that changes to shared policies could take longer than usual to reach destination accounts. At 10:44 UTC Cloudflare posted that it was continuing to investigate, with no new detail added. By 10:47 UTC Cloudflare said a fix had been implemented and it was monitoring the results, and the incident closed out at 39 minutes with no further update filed. That is three updates in total for the whole incident, which is a thin record to work from, but it is what Cloudflare published. No user reports were filed during this window. Cloudflare's status page does not say what caused the degraded availability, only that a fix went in. Over the past 90 days Cloudflare has logged 195 incidents with a median duration of 1 hour 47 minutes, so this one resolved faster than Cloudflare's own recent median.
Learning
If you rely on Cloudflare's CASB for policy sharing between accounts in Cloudflare Organizations, this is the kind of failure that will not show up if you are only watching your own endpoints: the delay sat inside Cloudflare's internal findings pipeline and policy propagation, not in your traffic or your DNS resolution. UptimeRobot's own probes across api-control, dns-1111 and edge-data in the EU and North America stayed at 100% uptime for 24 hours, 7 days and 30 days, which is correct, because those checks were not pointed at CASB and had no reason to flag anything. Both readings are true at once: your product kept resolving and serving fine, while Cloudflare's CASB findings and cross-account policy propagation lagged behind for 39 minutes. That is the general shape of a provider-side control-plane issue, the parts you can reach stay up, the parts you cannot reach from outside quietly slow down. Your own monitoring covers your half of this relationship. UptimeRobot now watches the provider's half too, so next time something like this happens you know which side broke without guessing.