A Microsoft logo is seen outside the headquarters of Microsoft Germany GmbH in Cologne, North Rhine-Westphalia, Germany, July 28, 2026. /VCG
Alphabet-owned cybersecurity firm Wiz said on Thursday it had found a sweeping flaw that could have compromised thousands of Microsoft cloud customers.
The now-patched vulnerability in a key Microsoft database service, Azure CosmosDB, would have allowed a hacker to remotely access any user's data, Wiz said.
Microsoft said the issue had been "fully addressed" in cooperation with Wiz and that they had found "no evidence of customer impact" in investigations. It did not say how many customers could have been affected.
CosmosDB is a core part of Microsoft's cloud offerings, estimated to have thousands of customers.
It stores data used in chatbots, web applications and online retail recommendation engines. It also powers Microsoft Teams and Copilot.
"When you build in the cloud, and when it's on Microsoft, it's usually in CosmosDB," said Wiz Chief Technology Officer Ami Luttwak.
The finding is the latest in a series of vulnerabilities. Wiz discovered a similar CosmosDB flaw in 2021 that researchers say could have allowed the mass compromise of cloud users before it was patched. Last year, researcher Dirk-jan Mollema found another flaw, also since patched, that could have allowed mass hijacking of Microsoft cloud users' accounts.
Outside researchers said the latest flaw discovered by Wiz was serious.
"It's not good," said Karl Fosaaen, a senior vice president at Minneapolis-based cybersecurity firm NetSpi. "CosmosDB does have some pretty heavy usage and there is frequently sensitive data that ends up in it," he said. But he cautioned that such discoveries happen periodically across cloud services.
Vaisha Bernard, co-owner of Dutch cybersecurity firm Eye Security, said researchers have recently been finding "a lot of high-severity cloud vulnerabilities at infrastructure providers." Had a hacker found the CosmosDB flaw before Wiz did, "they most definitely could have caused some pretty serious damage."
CHOOSE YOUR LANGUAGE
互联网新闻信息许可证10120180008
Disinformation report hotline: 010-85061466