The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, Cloudflare disclosed a critical vulnerability in its Containers and Sandboxes service that allowed Workers Paid account holders to access residual data from other customers' containers on shared physical hosts. The flaw, reported by security researcher Oren Yomtov from Accomplish, stemmed from a misconfigured shared storage pool that skipped zeroing reused 64 KiB blocks. By writing only 4 KiB to unused regions, attackers could access up to 60 KiB of unwiped data from previous tenants, including SQLite databases, credentials, and application files. Researchers found exploitable residual data on 18 of 24 tested container placements across 20 of 22 nodes. This incident highlights the persistent challenges of maintaining tenant isolation in multi-tenant cloud environments, particularly as organizations increasingly rely on containerized workloads and serverless computing platforms for business-critical applications and data processing.

Why This Matters Now

Multi-tenant isolation failures are becoming more critical as organizations accelerate cloud adoption and containerization. This incident demonstrates how storage-level misconfigurations can bypass application-layer security controls, exposing sensitive customer data across tenant boundaries in ways that traditional perimeter defenses cannot prevent.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability was caused by a misconfigured shared storage pool that skipped zeroing reused 64 KiB blocks, allowing attackers to access up to 60 KiB of residual data from previous customers' containers.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this cross-tenant container vulnerability by constraining lateral movement between workloads and limiting systematic data access across shared infrastructure nodes.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust architecture would likely constrain the attacker's ability to freely create containers across shared infrastructure by applying workload-level security policies and identity verification requirements

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Segmentation policies would likely limit the attacker's ability to manipulate containers across tenant boundaries by enforcing strict workload isolation and reducing access to shared storage resources

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west security controls would likely constrain the attacker's systematic movement across infrastructure nodes by enforcing workload-to-workload communication policies and restricting cross-node container deployment patterns

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Visibility and control mechanisms would likely detect and constrain systematic script execution patterns across multiple container instances, reducing the attacker's ability to orchestrate coordinated data discovery operations

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely constrain the attacker's ability to extract recovered data by monitoring and controlling outbound data flows from compromised containers across multiple infrastructure nodes

Impact (Mitigations)

While cross-tenant data exposure occurred, Zero Trust controls would likely have reduced the overall scope of accessible customer data and limited the attacker's reach across infrastructure boundaries

Impact at a Glance

Affected Business Functions

  • Cloud Application Hosting
  • Containerized Workload Management
  • Backend Service Operations
  • Code Execution Environments
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of residual customer data including directory structures, SQLite databases, Chromium profiles, .env files, and credential files from previously deleted containers. The vulnerability affected Cloudflare Workers Paid plan customers using the Containers service, with researchers finding residual material on 18 of 24 container placements tested across 20 of 22 underlying nodes.

Recommended Actions

  • • Implement Zero Trust Segmentation with strict tenant isolation boundaries and namespace enforcement to prevent cross-tenant data access
  • • Deploy Multicloud Visibility & Control to detect anomalous container creation patterns and repeated malformed storage allocation requests
  • • Establish Egress Security & Policy Enforcement to monitor and control outbound data flows from containerized workloads
  • • Enable Kubernetes Security (AKF) with pod-to-pod segmentation and namespace enforcement for container runtime protection
  • • Activate Cloud Native Security Fabric (CNSF) for real-time inspection and distributed policy enforcement across shared infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image