Check Point Research disclosed five vulnerabilities in workerd, the open-source runtime behind Cloudflare Workers and Cloudflare Code Mode, describing two primary attack paths: cross-tenant memory exposure in the managed Workers environment and a sandbox escape in Code Mode that can lead to native code execution on the host in self-hosted deployments. The researchers said the issues stem from native C++ glue code and the tcmalloc heap operating outside core V8 isolation protections, creating exploitable conditions even where V8 sandboxing and memory protection keys are enabled.
Cloudflare rated two of the flaws Critical and said fixes have already been deployed in the managed Workers production environment. Organizations running self-hosted deployments were advised to upgrade to workerd v1.20260619.1, while Check Point said it has released proof-of-concept code alongside its Black Hat USA 2026 presentation, increasing the urgency for defenders to validate patch status and review exposure in any self-managed workerd instances.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research submitted four of the five discovered workerd vulnerabilities to Cloudflare through HackerOne under coordinated disclosure. The reports covered issues later tied to Cloudflare Workers and Code Mode impact.
Check Point Research publicly released proof-of-concept code for the vulnerabilities as part of its Black Hat USA 2026 presentation. The release accompanied public disclosure of the attack paths affecting Cloudflare Workers and Code Mode.
Cloudflare released workerd version 1.20260619.1 to remediate the reported vulnerabilities in self-hosted deployments. The company rated two of the five vulnerabilities as Critical.
Cloudflare confirmed to the researchers that the vulnerabilities reproduced on production, except for the original URLPattern implementation, and that the tcmalloc heap sat outside V8 sandbox and memory protection key protections. Cloudflare also fixed the managed Workers environment in production.
Based on the discovered bugs, Check Point Research built two end-to-end exploit chains: one demonstrating cross-tenant secret leakage in Workers and another achieving host native code execution from a prompt-injection starting point in self-hosted Code Mode testing. The researchers said they did not run the cross-tenant exploit on Cloudflare production because a crash could affect other tenants.
Check Point Research analyzed Cloudflare Code Mode and the underlying open-source workerd runtime, identifying five vulnerabilities in native C++ components. The issues included URLPattern out-of-bounds reads, zlib and HTMLRewriter use-after-free bugs, and a Durable Objects KV SQL bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceresearch.checkpoint.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.