The record
Written from the 1 report below. Nothing here is unsourced.
- Microsoft has patched a vulnerability in Azure Cosmos DB, code-named CosmosEscape by security firm Wiz, that could have let attackers escape a query sandbox and gain full access to databases across customer tenants, including a platform-wide signing key.
- The flaw was reported in November 2025, with an initial block within 48 hours and a full fix across all regions completed in July 2026.
- Microsoft says its investigation found no unauthorized access and no customer data was affected, and no customer action is required.
- The issue matters because Cosmos DB hosts data for widely used services such as Teams and Copilot, though Wiz did not report accessing that data.
What to watch next
- Wiz's full technical presentation of the exploit chain at Black Hat USA on August 6
- Wiz's response on the exploit's exact prerequisites and tested scope
- Whether Microsoft assigns a CVE identifier or severity score, and details on how long the exposure window lasted
Coverage1
1 report
English national1
All filed from India
Named United States · Azure Cosmos DB · Black Hat USA · Microsoft · Wiz
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
