70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit – PoC Released
ID: 7ee122c7-4052-58bc-8620-88af9a7b09b6
STIX ID: report--7ee122c7-4052-58bc-8620-88af9a7b09b6
Feed Name: cybersecurityNews.com
MongoBleed (CVE-2025-14847) is a critical unauthenticated remote vulnerability in MongoDB's zlib compression that can return uninitialized heap memory and expose credentials, API keys, tokens, and other sensitive data; over ~74,000 potentially unpatched instances were identified, public exploit code is available, active exploitation has been confirmed (including impacts to Ubisoft), and MongoDB has released patches while recommending disabling zlib compression for self-hosted instances until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
