Select a theme from the list.
Insights

From our experts

Latest
SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack Playbook
Security Insight

Cloudflare Container Flaw Broke the Wall Between Customer Workloads

Cloudflare Container Flaw Broke the Wall Between Customer Workloads
Photo by Christina Morillo on Pexels

Cloudflare has corrected a storage isolation flaw that could have allowed one paying customer to recover residual files from containers previously used by other tenants. The weakness affected Cloudflare Containers and Sandboxes, potentially exposing application data, database pages, environment files and credentials left in reused storage blocks. Cloudflare says it found no evidence of customer data exposure and completed infrastructure-wide mitigation.

News Date: 2026-09-27

Cloudflare has fixed a cross-tenant storage vulnerability affecting its Containers and Sandboxes services. The flaw created a path for a customer with a Workers Paid account to recover fragments of data left behind by other customers whose workloads had previously occupied the same physical storage.

How residual data became readable

The problem involved a shared storage pool that did not properly erase reused 64 KiB blocks. When a container disk was deleted, its physical blocks returned to a pool serving workloads from multiple customer accounts. A new container could write a small amount of data to one of those blocks while leaving much of its previous content intact and readable.

Researchers encountered residual material across a significant portion of their test placements. Recoverable information included directory structures, SQLite database pages, Chromium profiles, environment files and credential-related files. The attacker could not select a particular victim, access an active disk or modify another tenant's workload, but random disclosure is still a serious failure of cloud isolation.

Cloudflare's response

Cloudflare removed the configuration that skipped storage-block zeroing, retired existing container disks and cleared cached snapshots that might preserve old mappings. The company completed mitigation by September 19 and deployed the changes automatically, so customers do not need to install an update.

Cloudflare also reviewed historical telemetry and reported finding no evidence that the technique had been used to expose customer information. The security researchers limited their testing to validation scripts and aggregate measurements rather than collecting actual customer files.

Lessons for cloud customers

  • Avoid storing long-lived credentials in container filesystems.
  • Use managed secret stores and short-lived workload identities.
  • Remove sensitive temporary files before terminating workloads.
  • Include provider isolation failures in cloud risk assessments.

In my view, the incident is a reminder that a sandbox is only as strong as every infrastructure layer underneath it. Container isolation, access controls and application security cannot compensate for storage that retains another tenant's data. Cloud providers should treat secure block erasure as a foundational control, while customers should design workloads on the assumption that temporary disks are not appropriate places for durable secrets.

Talk to our team →

Latest

SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksSep 28, 2026Lunex Leaves Security Tools Running but Blind Before Raiding BrowsersSep 28, 2026Cloudflare Container Flaw Broke the Wall Between Customer WorkloadsSep 28, 2026Storm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutSep 27, 2026One Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftSep 27, 2026Clop Ransomware Gang Gets Hacked Through Its Own Outdated CMSSep 27, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards