Feeds.4Sysops Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB to Potential Attacks
Article Content
- •CosmosEscape vulnerability could compromise all databases in Azure Cosmos DB.
- •Attackers could acquire the Cosmos Master Key, enabling full access to databases.
- •Microsoft has remediated the issue, but organizations should review their security measures.
Wiz Research disclosed a critical vulnerability named CosmosEscape in Azure Cosmos DB, allowing attackers to potentially compromise every database in the service, including Microsoft's internal systems like Entra ID, Teams, and Copilot. The flaw, residing in the Gremlin API, could have enabled attackers to acquire the Cosmos Master Key, granting full read and write access to databases. This vulnerability posed a significant risk of cross-tenant attacks, potentially impacting millions of workloads. Microsoft has since remediated the issue by eliminating the Cosmos Master Key and has confirmed no evidence of exploitation. Security experts emphasize the importance of reviewing security postures despite the patch, as traditional tools may not detect such vulnerabilities. The incident serves as a reminder of the inherent risks in shared cloud infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Microsoft and CVE-2024-27348 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…