logo

CISA Warns of Actively Exploited MongoDB Server Vulnerability (CVE-2025-14847)

ID: 30d87211-b8f1-57ee-a206-5245f040087a

STIX ID: report--30d87211-b8f1-57ee-a206-5245f040087a

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-12-30

Date Updated: 2026-04-19

Author: AnuPriya

...
...

CISA has issued a critical warning that CVE-2025-14847 — an improper length parameter handling vulnerability in MongoDB Server's Zlib-compressed protocol headers — is being actively exploited in the wild. The flaw (CVSS 9.1) permits unauthenticated remote reads of uninitialized heap memory, potentially exposing sensitive data; organizations are urged to apply vendor patches or follow BOD 22-01 mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.