By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Use. You can change your cookie settings through your browser.
A Microsoft logo is seen outside the headquarters of Microsoft Germany GmbH in Cologne, North Rhine-Westphalia, Germany, July 28, 2026. /VCG
A Microsoft logo is seen outside the headquarters of Microsoft Germany GmbH in Cologne, North Rhine-Westphalia, Germany, July 28, 2026. /VCG
Alphabet-owned cybersecurity firm Wiz said on Thursday it had found a sweeping flaw that could have compromised thousands of Microsoft cloud customers.
The now-patched vulnerability in a key Microsoft database service, Azure CosmosDB, would have allowed a hacker to remotely access any user's data, Wiz said.
Microsoft said the issue had been "fully addressed" in cooperation with Wiz and that they had found "no evidence of customer impact" in investigations. It did not say how many customers could have been affected.
CosmosDB is a core part of Microsoft's cloud offerings, estimated to have thousands of customers.
It stores data used in chatbots, web applications and online retail recommendation engines. It also powers Microsoft Teams and Copilot.
"When you build in the cloud, and when it's on Microsoft, it's usually in CosmosDB," said Wiz Chief Technology Officer Ami Luttwak.
The finding is the latest in a series of vulnerabilities. Wiz discovered a similar CosmosDB flaw in 2021 that researchers say could have allowed the mass compromise of cloud users before it was patched. Last year, researcher Dirk-jan Mollema found another flaw, also since patched, that could have allowed mass hijacking of Microsoft cloud users' accounts.
Outside researchers said the latest flaw discovered by Wiz was serious.
"It's not good," said Karl Fosaaen, a senior vice president at Minneapolis-based cybersecurity firm NetSpi. "CosmosDB does have some pretty heavy usage and there is frequently sensitive data that ends up in it," he said. But he cautioned that such discoveries happen periodically across cloud services.
Vaisha Bernard, co-owner of Dutch cybersecurity firm Eye Security, said researchers have recently been finding "a lot of high-severity cloud vulnerabilities at infrastructure providers." Had a hacker found the CosmosDB flaw before Wiz did, "they most definitely could have caused some pretty serious damage."
A Microsoft logo is seen outside the headquarters of Microsoft Germany GmbH in Cologne, North Rhine-Westphalia, Germany, July 28, 2026. /VCG
Alphabet-owned cybersecurity firm Wiz said on Thursday it had found a sweeping flaw that could have compromised thousands of Microsoft cloud customers.
The now-patched vulnerability in a key Microsoft database service, Azure CosmosDB, would have allowed a hacker to remotely access any user's data, Wiz said.
Microsoft said the issue had been "fully addressed" in cooperation with Wiz and that they had found "no evidence of customer impact" in investigations. It did not say how many customers could have been affected.
CosmosDB is a core part of Microsoft's cloud offerings, estimated to have thousands of customers.
It stores data used in chatbots, web applications and online retail recommendation engines. It also powers Microsoft Teams and Copilot.
"When you build in the cloud, and when it's on Microsoft, it's usually in CosmosDB," said Wiz Chief Technology Officer Ami Luttwak.
The finding is the latest in a series of vulnerabilities. Wiz discovered a similar CosmosDB flaw in 2021 that researchers say could have allowed the mass compromise of cloud users before it was patched. Last year, researcher Dirk-jan Mollema found another flaw, also since patched, that could have allowed mass hijacking of Microsoft cloud users' accounts.
Outside researchers said the latest flaw discovered by Wiz was serious.
"It's not good," said Karl Fosaaen, a senior vice president at Minneapolis-based cybersecurity firm NetSpi. "CosmosDB does have some pretty heavy usage and there is frequently sensitive data that ends up in it," he said. But he cautioned that such discoveries happen periodically across cloud services.
Vaisha Bernard, co-owner of Dutch cybersecurity firm Eye Security, said researchers have recently been finding "a lot of high-severity cloud vulnerabilities at infrastructure providers." Had a hacker found the CosmosDB flaw before Wiz did, "they most definitely could have caused some pretty serious damage."