What happened
Cloudflare announced (Aug 14, 2026) new Cloudflare One capabilities: Gateway now natively detects MCP traffic via protocol headers (Mcp-Protocol-Version, Mcp-Method, Mcp-Name), exposes an experimental.is_mcp policy selector, and adds an AI Security dashboard showing MCP server/user discovery, plus Access for Workers to enforce identity-aware auth on self-hosted MCP endpoints.
Why it matters
Shadow MCP connections bypass approved enterprise tool governance; this closes the visibility gap for remote/managed-path MCP traffic (though not local stdio), directly addressing a widely-cited agentic attack surface (21,000+ exposed MCP servers, ~92% lacking OAuth per third-party research cited alongside the launch).
Applicability
Enterprise security/network teams using Cloudflare One should inventory MCP traffic and move to Portal-only enforcement within 30 days; complements existing MCP Server Portals feature.