The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, security researcher Oren Yomtov discovered a critical vulnerability in Cloudflare Containers that allowed one customer's container to access leftover disk data from other customers' previously deleted containers. The flaw stemmed from improper disk provisioning configuration where deleted container blocks were returned to a shared pool without proper wiping, enabling cross-tenant data exposure. Researchers successfully recovered directory structures, SQLite databases, browser profiles, and credential files across 18 of 24 test attempts on production servers spanning four continents. Cloudflare fixed the issue by enabling proper block wiping and retiring all running containers, completing remediation on September 19, 2026.

This incident highlights the growing risks in multi-tenant cloud infrastructure as organizations increasingly adopt containerized workloads and AI-driven development environments, making proper data isolation and secure deprovisioning critical for preventing cross-customer data breaches.

Why This Matters Now

Multi-tenant cloud vulnerabilities are increasingly critical as organizations migrate sensitive workloads to shared infrastructure and adopt AI-powered development platforms, making cross-tenant data isolation failures a significant compliance and security risk.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability exploited improper thin provisioning configuration where deleted container disk blocks were returned to a shared pool without wiping, allowing new containers to access previous customers' leftover data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have reduced the blast radius of this cross-tenant data exposure by constraining lateral movement paths and limiting the scope of credential-based pivoting across customer environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Workload isolation policies would likely have constrained the attacker's ability to access cross-tenant disk blocks by implementing stricter container boundary controls and resource allocation segmentation

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have limited the attacker's ability to access raw disk operations and cross-tenant credential files by restricting process-level access to sensitive system resources

Lateral Movement

Control: East-West Traffic Security

Mitigation: Traffic inspection and segmentation controls would likely have constrained credential-based lateral movement by blocking unauthorized inter-tenant communication paths and validating identity context for cross-environment access

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility and policy enforcement would likely have detected and constrained persistent access patterns across geographic regions by monitoring anomalous cross-tenant activity and container behavior

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained large-scale data extraction by monitoring and restricting outbound data flows containing sensitive cross-tenant information like databases and credential files

Impact (Mitigations)

The residual impact would likely have been constrained to fewer affected customers and reduced data exposure scope, limiting the overall blast radius of cross-tenant credential compromise

Impact at a Glance

Affected Business Functions

  • Cloud Computing Services
  • Container Hosting
  • Serverless Computing
  • Multi-tenant Infrastructure
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Cross-tenant data leakage affecting Cloudflare Containers and Sandboxes customers. Exposed data included directory structures, SQLite databases, Chromium browser profiles, environment files, and credential files from other customers' containers. The vulnerability allowed reading up to 60KB of leftover data from previously allocated disk blocks across shared infrastructure.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent cross-tenant data access even in shared infrastructure scenarios
  • • Deploy Multicloud Visibility & Control to detect anomalous disk access patterns and unauthorized data reads across container environments
  • • Establish Egress Security & Policy Enforcement to monitor and control data exfiltration attempts from container workloads
  • • Enable Threat Detection & Anomaly Response capabilities to baseline normal container behavior and alert on suspicious disk-level operations
  • • Enforce Cloud Native Security Fabric controls with real-time inspection and distributed policy enforcement for container isolation and data protection

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image