Cloudflare fixes Containers cross-tenant flaw exposing customer data

BleepingComputer

Overview

Cloudflare has addressed a security flaw in its Containers and Sandboxes feature that allowed users with a Workers Paid account to access leftover data from other customers' containers located on the same physical server. This vulnerability raised serious privacy concerns, as it meant that sensitive information from one customer could potentially be retrieved by another. Cloudflare has not disclosed the specific number of users affected, but given the nature of the service, it could impact a significant number of businesses relying on this technology. The company has now implemented a fix to prevent such unauthorized access, emphasizing the importance of data isolation in cloud environments. Customers are advised to stay updated on security measures and ensure their data remains protected.

Key Takeaways

  • Affected Systems: Cloudflare Containers and Sandboxes for Workers Paid accounts
  • Action Required: Cloudflare has implemented a fix to address the vulnerability.
  • Timeline: Disclosed on [specific date not provided]

Original Article Summary

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]

Impact

Cloudflare Containers and Sandboxes for Workers Paid accounts

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on [specific date not provided]

Remediation

Cloudflare has implemented a fix to address the vulnerability.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability.

Related Coverage

Citrix confirms two NetScaler RCE zero-days exploited in attacks

BleepingComputer

Citrix has confirmed that two serious vulnerabilities in its NetScaler product, identified as CVE-2026-88771 and CVE-2026-88772, are currently being exploited in attacks. These vulnerabilities allow remote code execution, which means that attackers could potentially take control of affected systems. Organizations using NetScaler should prioritize applying the security updates released by Citrix to mitigate these risks. The situation is urgent, as the vulnerabilities are actively being exploited, putting many businesses at risk of unauthorized access and data breaches. Users are advised to stay vigilant and ensure their systems are up to date with the latest patches.

Sep 27, 2026

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

SecurityWeek

The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in Microsoft SharePoint, identified as CVE-2026-65660, to its Known Exploited Vulnerabilities (KEV) catalog. This flaw is currently being exploited in the wild, prompting CISA to issue a patching deadline for federal agencies by September 28. Organizations using SharePoint should prioritize applying the necessary updates to mitigate potential risks. The urgency of this situation lies in the fact that attackers can leverage this vulnerability for unauthorized access, which could lead to data breaches and other security incidents. It's crucial for users to stay informed and act quickly to secure their systems.

Sep 27, 2026

Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents

Help Net Security

Last week, a significant data breach involving Gyazo was reported, exposing the personal information of 23.6 million users. The breach has raised concerns about the security of user data on the popular screenshot-sharing platform. Attackers managed to access sensitive information, including email addresses and user-generated content, which could lead to identity theft or phishing attacks. This incident underscores the importance of robust security measures for online services that handle sensitive user data. Users of Gyazo are advised to change their passwords and monitor their accounts for any suspicious activity.

Sep 27, 2026

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

The Hacker News

Security researchers have identified two serious unpatched vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that can allow attackers to execute remote code. These zero-day flaws are currently being exploited in the wild, raising concerns among IT administrators. Citrix has not yet acknowledged the vulnerabilities or provided a fix, leading some organizations to proactively take their appliances offline to prevent potential attacks. The situation is urgent as these vulnerabilities could expose sensitive data and systems to unauthorized access. Companies using affected Citrix products should monitor for updates and consider temporary mitigation strategies until a patch is released.

Sep 27, 2026

Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams

Hackread – Cybersecurity News, Data Breaches, AI and More

Researchers at Manifold Security discovered a significant issue involving placeholder domains that were found in 359,000 GitHub files and linked to 349 AI agent skills. These domains are being used to redirect users to various scams, which could lead to financial losses and data theft. This situation raises concerns about the security of AI integrations and the potential for users to fall victim to these scams. It highlights the importance of scrutinizing third-party skills and applications, especially those that rely on external domains. Users and developers need to be vigilant about the sources of the tools they use to avoid being exploited by malicious actors.

Sep 26, 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Hacker News

A new malware called Lunex, which is part of a broader malware-as-a-service model, is targeting Ukrainian-speaking users through compromised websites. The attack involves a four-stage process starting with a fake CAPTCHA page designed to lure victims. Once engaged, the malware exploits an AMD driver to disable security monitoring, making it easier to steal sensitive information, such as browser credentials. This is particularly concerning as it highlights the tactics used by cybercriminals to bypass security measures and compromise user data. The findings from the cybersecurity firm Ontinue emphasize the need for increased vigilance among users, especially in regions facing heightened cyber threats.

Sep 26, 2026