Find notable cyber news and cases, enriched with sources, timelines, and signals.

Azure Cosmos DB Gremlin query sandbox escape security flaw

Vulnerability
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A now-patched Azure Cosmos DB vulnerability let an attacker escape the Gremlin query sandbox and could expose full read and write access across customer tenants. The exploit chain used a crafted Gremlin query, .NET reflection, and code execution on a multi-tenant gateway to reach a platform-wide signing secret. That secret and a regional account directory could be used to retrieve a target's primary account key and broaden access across tenants and APIs. Microsoft blocked the vulnerable entry point within 48 hours of the November 2025 report and completed the broader fix across all regions in July 2026.

Related Happenings

Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)

Vulnerability
H score37 First: 24.07.2026 17:15 Last: 24.07.2026 17:15 Sources 1

About this happening: CVE-2026-54121 (Certighost) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker obtain a certificate for...

Storm-2949 Microsoft 365 and Azure data-theft campaign

Campaign
H score33 First: 19.05.2026 22:35 Last: 19.05.2026 22:35 Sources 1

About this happening: The Storm-2949 campaign is targeting Microsoft 365 and Azure production environments to steal sensitive data, increasing the risk of privileged-account takeover and cloud...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Windows BlueHammer local public exploit privilege-escalation flaw

Vulnerability
H score47 First: 06.04.2026 22:19 Last: 06.04.2026 22:19 Sources 1

About this happening: BlueHammer (CVE-2026-33825) is a Microsoft Defender local privilege-escalation vulnerability that Microsoft patched on April 14 but that has since been abused in *...

Latest development: 23.04.2026 14:05

CISA added CVE-2026-33825, known as BlueHammer, to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch Windows and Microsoft Defender systems within two weeks, with remediation due by May 7, after evidence that attackers were exploiting the flaw in zero-day attacks.

Microsoft SharePoint actively exploited unauthenticated RCE (CVE-2026-20963)

Vulnerability
H score37 First: 19.03.2026 12:06 Last: 19.03.2026 12:06 Sources 1

About this happening: CVE-2026-20963 is now being exploited in attacks against Microsoft SharePoint deployments, creating unauthenticated remote code execution risk for unpatched servers*...

Timeline

  1. 30.07.2026 16:34 2 articles · 2h ago

    Wiz discloses CosmosEscape in Azure Cosmos DB

    Initial Disclosure

    Wiz said a now-patched Azure Cosmos DB flaw, codenamed CosmosEscape, could let an attacker escape the Gremlin query sandbox and obtain full read and write access across customer tenants by starting with a crafted query against an attacker-controlled Gremlin database. The researchers said the chain reached code execution on the DB Gateway, exposed a platform-wide signing secret and a regional Config Store, and could be used to retrieve a target's primary account key; Microsoft said it blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report, completed the broader fix across all regions in July 2026, and found no unauthorized activity or customer data access.

    Show sources