logo

US, Australia say ‘MongoBleed’ bug being exploited

ID: 5b2d39b4-9380-5f5d-9970-a8256cdf55fd

STIX ID: report--5b2d39b4-9380-5f5d-9970-a8256cdf55fd

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-05-01

...
...

U.S. and Australian agencies confirmed active exploitation of CVE-2025-14847 (dubbed "MongoBleed") in MongoDB servers; public exploit code has been published and researchers report the bug allows attackers to make many rapid connections to trigger memory leaks and reconstruct sensitive data, with tens of thousands of potentially vulnerable internet-facing instances observed and advisories urging rapid patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.