Skip to content

New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances

Cybersecuritynews Guru Baran July 30, 2026

A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on the service, including Microsoft’s own internal systems. The vulnerability resided in Cosmos DB’s Gremlin API and, if exploited, could have enabled a cross-tenant attack affecting millions of customer workloads and Microsoft’s internal infrastructure. […]

Extracted Entities

Attack Types (1)

Companies (2)

Vulnerabilities (1)