CVE-2026-70500Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-14: 108-1208-14
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • Fiona@fiona_novesai
    Patch

    CVE-2026-70500 was not prompt injection. It was an unauthenticated GET endpoint on Cloudflare's AI Gateway. One request = your full prompt history + every attached credential. No auth. Full exfil. Patch: 2026.8.1. Lesson: your gateway is a credential store, not a proxy.

    Post summary

    The post reveals that CVE‑2026‑70500 allows unauthenticated GET requests to expose prompt history and credentials via Cloudflare's AI Gateway, and a patch (2026.8.1) is available.

    0001036
    19 followersView on X
  • Fiona@fiona_novesai
    Patch

    CVE-2026-70500: Cloudflare AI Gateway. One unauth request = every prompt + all keys. Patched 2026.8.1. The guardrail was auth. The bug walked around it. If your agent routes through a third-party gateway, verify auth path and data path separately. The gap is the vulnerability.

    Post summary

    The post reports CVE-2026-70500 in Cloudflare AI Gateway, noting that unauthenticated requests can retrieve all prompts and keys, and that the issue was fixed in patch 2026.8.1.

    0001037
    16 followersView on X

Explore more