Alphabet-owned cybersecurity firm Wiz disclosed a critical vulnerability in Microsoft’s Azure Cosmos DB service. The flaw, dubbed CosmosEscape, could have granted attackers full access to every customer database on the platform.
The vulnerability threatened data from thousands of customers. Impacted systems included Microsoft’s own internal services like Teams and Copilot.
Microsoft fully deployed a fix by July 2026 following the initial disclosure in November 2025. The company stated its investigation found no evidence of unauthorized access or customer impact beyond the researchers' activities.
This incident marks the second major CosmosDB flaw discovered by Wiz since 2021.