[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:critical-flaw-led-to-azure-cosmos-db-pwnage-msbks1d0":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"a3ce4228-6a6f-4dbe-8f9b-10f1a73fc3a6","Critical Flaw Led to Azure Cosmos DB Pwnage","critical-flaw-led-to-azure-cosmos-db-pwnage-msbks1d0","A critical vulnerability in Azure Cosmos DB (CosmosEscape) allowed attackers to extract platform-wide master keys via the Gremlin API, granting full read\u002Fwrite access to any Cosmos DB instance. All Cosmos DB customers and Microsoft internal databases were potentially exposed. Microsoft deployed hotfixes, but we need to assume compromise during the disclosure window.","critical","advisory",[],[13,14,15,16,17],"Azure Cosmos DB","Microsoft","Entra ID","Teams","Copilot","Immediately audit Azure Cosmos DB access logs and master key rotation timestamps. Cross-reference with your organization's Cosmos DB instances to identify any unauthorized key access or data exfiltration between vulnerability discovery and patching. Rotate all Cosmos DB master keys now if not done post-patch.",[20],"03c82bb3-cc8a-47a6-88df-1e9e9f7f93fc",null,[23],"https:\u002F\u002Fwww.securityweek.com\u002Fcritical-flaw-led-to-azure-cosmos-db-pwnage\u002F","active","2026-08-04T09:05:40.886+00:00","2026-08-02T09:05:44.176258+00:00","2026-08-02T09:09:34.503025+00:00",[29],{"id":20,"title":6,"url":23}]