70,000+ MongoDB Servers Vulnerable to MongoBleed Exploit as PoC Is Released
ID: a1c3ac52-fc12-542e-888b-3598217d6f54
STIX ID: report--a1c3ac52-fc12-542e-888b-3598217d6f54
Feed Name: Cyber Press
**Executive summary:** CVE-2025-14847 ("MongoBleed") is a critical, unauthenticated memory-disclosure vulnerability in MongoDB's zlib compression implementation; proof-of-concept exploit code has been published and active exploitation has been observed. Shadowserver reports 74,854 exposed, unpatched MongoDB instances (≈95% of exposed servers) across versions from 3.6 through 8.2.x. MongoDB released emergency patches (8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, 4.4.30) and recommends disabling zlib compression as a temporary mitigation; administrators should patch immediately and enable authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
