Cloudflare isolation failure exposed residual cross-customer data

Cloudflare isolation failure exposed residual cross-customer data. Cloud customers faced a potential cross-tenant data leak because reused storage blocks were not fully cleared.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 28th, 2026.

Cloud customers faced a potential cross-tenant data leak because reused storage blocks were not fully cleared. A Workers Paid customer could have recovered residual files from previous Containers or Sandboxes running on the same physical host. During testing, residual material appeared on 18 of 24 placements and 20 of 22 nodes. That material included database pages, directory structures, and credential files. Cloudflare says the researchers didn’t access real customer contents, and its review found no evidence of exploitation.

The issue crossed a core tenant-isolation boundary. However, it didn’t allow someone to read active disks, change another customer’s data, or disrupt workloads. Cloudflare removed the problematic setting, retired existing disks, and cleared cached snapshots by September 19th, 2026.

For leaders, shared-cloud assurance needs to include data-remanence controls, not just logical access policies. For defenders, no remediation is required, but it’s still worth reviewing whether sensitive secrets were stored in container filesystems. Secure deletion remains essential in multi-tenant infrastructure. Review secret-storage practices for cloud containers even though Cloudflare has completed the infrastructure fix.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Cloudflare isolation failure exposed residual cross-customer data
Broadcast by