Thehackernews Cloudflare Containers Vulnerability Exposes Customer Data
Article Content
- •Cloudflare fixed a vulnerability allowing data access from deleted containers.
- •Residual data included sensitive files like SQLite databases and credentials.
- •Cloudflare implemented a two-stage fix to mitigate the issue.
On September 4, 2026, Oren Yomtov from Accomplish reported a vulnerability in Cloudflare Containers that allowed customers to access residual disk data from deleted containers of other accounts. The flaw stemmed from the use of Linux thin provisioning, which failed to wipe data before reassigning storage blocks. Researchers successfully retrieved sensitive data, including SQLite databases and credential files, from 18 out of 24 attempts across multiple servers. Cloudflare addressed the issue in two stages: reactivating block wiping on September 14 and retiring affected container disks by September 19. No evidence of malicious exploitation was found, and all recovered data was securely deleted. This incident highlights ongoing concerns about container security and the potential for data leaks in multi-tenant environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Cloudflare and CVE-2026-31431 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Multiple Critical CVEs Exploited in Cybersecurity Attacks A series of vulnerabilities, including CVE-2025-49144, CVE-2025-31702, and CVE-2026-46333, have been identified, affecting systems like Notepad++ and FortiWeb devices. These vulnerabilities allow for local privilege escalation, SQL injection, and remote code execution. Attackers exploit these flaws through various…