When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

2026-08-07T08:52:16Z15773ae8269bd50400dd1e7e54659c953d96708f4adf2c4ee5f6f629bdf26150
Cloudflare Code ModeCloudflare WorkersV8arbitrary code executionin-process sandboxmemory corruptionsandbox escapeserverless securityvulnerability researchworkerd

What happened

Check Point Research reports five memory-corruption vulnerabilities in workerd, the native C++ runtime underlying Cloudflare Code Mode and Workers. Because workerd relies on V8 for in-process isolation of untrusted code, exploitation may enable sandbox escape, arbitrary code execution, or compromise of workloads hosted in Cloudflare’s serverless environments. The document is a research-feed aggregation; specific vulnerability identifiers and affected versions are not provided in the supplied content.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
15773ae8269bd50400dd1e7e54659c953d96708f4adf2c4ee5f6f629bdf26150
Enrichment time
2026-08-07T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.