logo

MongoBleed flaw actively exploited in attacks in the wild

ID: 078f7b1c-5929-5940-aba9-30b51ff06ac2

STIX ID: report--078f7b1c-5929-5940-aba9-30b51ff06ac2

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-12-29

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical MongoDB vulnerability (CVE-2025-14847, 'MongoBleed', CVSS 8.7) allows unauthenticated attackers to leak server memory and potentially achieve remote code execution; a public proof-of-concept and reports of active exploitation affect over 87,000 potentially vulnerable instances worldwide. MongoDB has released patched versions and recommends immediate upgrade or disabling zlib compression as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.