logo

70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit – PoC Released

ID: 7ee122c7-4052-58bc-8620-88af9a7b09b6

STIX ID: report--7ee122c7-4052-58bc-8620-88af9a7b09b6

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-30

Date Updated: 2026-04-21

Author: Abinaya

...
...

MongoBleed (CVE-2025-14847) is a critical unauthenticated remote vulnerability in MongoDB's zlib compression that can return uninitialized heap memory and expose credentials, API keys, tokens, and other sensitive data; over ~74,000 potentially unpatched instances were identified, public exploit code is available, active exploitation has been confirmed (including impacts to Ubisoft), and MongoDB has released patches while recommending disabling zlib compression for self-hosted instances until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.