Cloudflare has published a new beta build of its Cloudflare One Client for Windows, identified in the changelog as version 2026.8.2028.1. The release is available from the beta releases downloads page, and the changelog frames it as a set of changes and improvements rather than a new product line. For developers and freelancers who run Cloudflare's Zero Trust client on Windows machines, the practical question is which of their recurring connectivity complaints this build claims to address.
The most operationally visible fix concerns split tunneling. According to the changelog, the client previously could briefly block traffic to split-tunnel excluded resources while it was connecting or reconnecting. That behavior matters because excluded resources are, by definition, the destinations a user expects to reach outside the tunnel; a transient block during connection setup can look like a broken local service rather than a VPN state change.
Attention was paid to reauthentication as well. According to Cloudflare, reliability for reauthentication has been raised, and a problem was resolved in which a fresh registration might be triggered by a reauthentication. Since a forced re-registration carries more weight than refreshing a credential, the modification addresses a failure mode in which a routine identity check grew into re-enrolling the device.
Regarding networking, better client behavior is described in the changelog for situations where the MTU of the current network is lowered. Added as well is the ability, when unrestricted LAN inclusion is enabled by policy or MDM, to route local IPv4 networks that are not RFC 1918 through the WARP tunnel. Environments where the local network falls outside the usual private address ranges, or where path MTU changes during a session, are what these changes together address.
DNS reliability on lower-MTU networks is addressed by clamping the TCP maximum segment size for DNS-over-HTTPS connections sent through the tunnel. This is a targeted transport-level adjustment: rather than changing which resolver is used, the client alters how large the DNS-over-HTTPS TCP segments may be, which is the kind of setting that matters when a path cannot carry full-size segments.
The changelog also reports improved API reliability by retrying requests dropped when reusing pooled connections. That is a client-side resilience change for connection reuse, a common source of intermittent failures that are hard to reproduce because they depend on timing and pool state.
Dependencies on Windows services are lowered by several changes, and recovery is improved. Running the Windows WLAN AutoConfig service is no longer necessary for the client, and a service recovery mechanism was implemented by Cloudflare, backed by a Windows scheduler task, that launches the WARP service on system unlock when it is not already active. With both changes, fewer preconditions exist for the tunnel to come up.
Hangs and crashes are the target of a cluster of fixes. Slow captive portal checks that made the client service unresponsive or caused a restart while connecting were fixed, per Cloudflare, along with a race that could stop WireGuard from connecting when tunnel protocols were switched during key rotation, and the client still reporting 'No network' following a successful manual disconnect.
Three further stability fixes are included. The first concerns a UI crash at startup, occurring on the client when a write to the Windows registry did not succeed. The second is a UI crash triggered when the daemon connection was reset in the middle of an IPC request. The third involves a startup crash that happened because date formatting data for the system locale had not yet been loaded. All of these are startup-path failures, and because the client may be prevented from running at all, they are disproportionately disruptive.
Two fixes concern hardware-backed identity and device posture. According to Cloudflare, one addressed latency spikes and traffic interruptions that occurred during TPM-backed API authentication when hardware-backed registration is enabled. The other corrected trailing whitespace in BIOS serial numbers, which had caused serial-number and client-certificate device posture checks to fail. The latter is a data-hygiene bug: a stray space in a firmware-reported string could break a posture evaluation.
For freelancers and small studios running Windows endpoints under Cloudflare Zero Trust, the practical implication is that this beta is worth evaluating specifically if you have seen split-tunnel resources drop during reconnect, repeated re-registration prompts, or posture checks failing on machines whose BIOS serial numbers contain padding. Because it is a beta build distributed through the beta downloads page, it is a candidate for a test machine rather than a blanket rollout, and the changelog does not state a general availability date.
The tradeoff is the usual one for beta client software: the fixes are described but not independently verified here, and the changelog does not quantify how often the addressed failures occurred, which Windows versions were exercised, or whether the new scheduler-backed service recovery interacts with existing enterprise management policies. The non-RFC 1918 routing support is explicitly conditional on unrestricted LAN inclusion being enabled by policy or MDM, so it will not apply to every deployment.
What remains unknown from the supplied material includes the release date of this specific build, whether it supersedes a prior beta, and whether any of these fixes are backported to the stable channel. The changelog also does not describe testing methodology or sample environments, so the claims should be read as vendor-reported changes rather than measured outcomes.
The reasonable conclusion for this audience is narrow and concrete: if your Windows Cloudflare One Client pain points match the list above, this beta names them directly, and the most defensible next step is a controlled trial on a non-critical machine while watching for regressions in tunnel establishment, DNS resolution and posture reporting.