logo

U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog

ID: 56b5206a-85f4-561d-a613-da476eed7c43

STIX ID: report--56b5206a-85f4-561d-a613-da476eed7c43

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-12-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The article reports that CISA added MongoDB Server vulnerability `CVE-2025-14847` (MongoBleed, CVSS 8.7) to its Known Exploited Vulnerabilities catalog after active exploitation was observed and a public proof-of-concept was released; more than 87,000 potentially vulnerable instances were identified worldwide. A wide range of MongoDB versions are affected, fixes are available in specific patched releases, and CISA ordered federal agencies to remediate by January 19, 2026 while recommending affected users upgrade immediately or disable zlib compression.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.