Azure Cosmos DB Gremlin query sandbox escape security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A now-patched Azure Cosmos DB vulnerability let an attacker escape the Gremlin query sandbox and could expose full read and write access across customer tenants. The exploit chain used a crafted Gremlin query, .NET reflection, and code execution on a multi-tenant gateway to reach a platform-wide signing secret. That secret and a regional account directory could be used to retrieve a target's primary account key and broaden access across tenants and APIs. Microsoft blocked the vulnerable entry point within 48 hours of the November 2025 report and completed the broader fix across all regions in July 2026.
Related Happenings
Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)
Vulnerability
H score37
First: 24.07.2026 17:15
Last: 24.07.2026 17:15
Sources 1
About this happening:
CVE-2026-54121 (Certighost) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker obtain a certificate for...
Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)
VulnerabilityAbout this happening: CVE-2026-54121 (Certighost) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker obtain a certificate for...
Storm-2949 Microsoft 365 and Azure data-theft campaign
Campaign
H score33
First: 19.05.2026 22:35
Last: 19.05.2026 22:35
Sources 1
About this happening:
The Storm-2949 campaign is targeting Microsoft 365 and Azure production environments to steal sensitive data, increasing the risk of privileged-account takeover and cloud...
Storm-2949 Microsoft 365 and Azure data-theft campaign
CampaignAbout this happening: The Storm-2949 campaign is targeting Microsoft 365 and Azure production environments to steal sensitive data, increasing the risk of privileged-account takeover and cloud...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Windows BlueHammer local public exploit privilege-escalation flaw
Vulnerability
H score47
First: 06.04.2026 22:19
Last: 06.04.2026 22:19
Sources 1
About this happening:
BlueHammer (CVE-2026-33825) is a Microsoft Defender local privilege-escalation vulnerability that Microsoft patched on April 14 but that has since been abused in *...
Windows BlueHammer local public exploit privilege-escalation flaw
VulnerabilityAbout this happening: BlueHammer (CVE-2026-33825) is a Microsoft Defender local privilege-escalation vulnerability that Microsoft patched on April 14 but that has since been abused in *...
Latest development: 23.04.2026 14:05
CISA added CVE-2026-33825, known as BlueHammer, to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch Windows and Microsoft Defender systems within two weeks, with remediation due by May 7, after evidence that attackers were exploiting the flaw in zero-day attacks.
Microsoft SharePoint actively exploited unauthenticated RCE (CVE-2026-20963)
Vulnerability
H score37
First: 19.03.2026 12:06
Last: 19.03.2026 12:06
Sources 1
About this happening:
CVE-2026-20963 is now being exploited in attacks against Microsoft SharePoint deployments, creating unauthenticated remote code execution risk for unpatched servers*...
Microsoft SharePoint actively exploited unauthenticated RCE (CVE-2026-20963)
VulnerabilityAbout this happening: CVE-2026-20963 is now being exploited in attacks against Microsoft SharePoint deployments, creating unauthenticated remote code execution risk for unpatched servers*...
Timeline
-
30.07.2026 16:34 2 articles · 2h ago
Wiz discloses CosmosEscape in Azure Cosmos DB
Initial DisclosureWiz said a now-patched Azure Cosmos DB flaw, codenamed CosmosEscape, could let an attacker escape the Gremlin query sandbox and obtain full read and write access across customer tenants by starting with a crafted query against an attacker-controlled Gremlin database. The researchers said the chain reached code execution on the DB Gateway, exposed a platform-wide signing secret and a regional Config Store, and could be used to retrieve a target's primary account key; Microsoft said it blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report, completed the broader fix across all regions in July 2026, and found no unauthorized activity or customer data access.
Show sources
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — thehackernews.com — 30.07.2026 16:34
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — thehackernews.com — 30.07.2026 16:34