Back to advisories

Critical Flaw Led to Azure Cosmos DB Pwnage

A critical vulnerability in Azure Cosmos DB (CosmosEscape) allowed attackers to extract platform-wide master keys via the Gremlin API, granting full read/write access to any Cosmos DB instance. All Cosmos DB customers and Microsoft internal databases were potentially exposed. Microsoft deployed hotfixes, but we need to assume compromise during the disclosure window.

CRITICALAdvisoryAug 02, 2026
Action required
Immediately audit Azure Cosmos DB access logs and master key rotation timestamps. Cross-reference with your organization's Cosmos DB instances to identify any unauthorized key access or data exfiltration between vulnerability discovery and patching. Rotate all Cosmos DB master keys now if not done post-patch.
Affected products
Azure Cosmos DBMicrosoftEntra IDTeamsCopilot