Wiz Research disclosed CosmosEscape, a vulnerability chain in Azure Cosmos DB where a crafted Gremlin query escaped the sandbox via .NET reflection, achieving code execution on the DB Gateway and exposing a platform-wide master key granting read/write access to every database on the service. Microsoft blocked the entry point within two days of the November 2025 report but required until July 2026 to fully rearchitect the credential model. The blast radius included Microsoft's own backends like Teams and Copilot. Community debate centered on three themes: the shared responsibility model (customers had no mitigation available), the legitimacy of the six-month remediation timeline given the scale of rearchitecting a live multi-tenant credential system, and concentration risk in hyperscaler environments. Notable gaps in the public record include no CVE, no CVSS score, no MSRC advisory, and no defined exposure window, leaving the assurance of 'no customer impact' without a clear denominator. The full chain is scheduled for Black Hat USA.