US, Australia say ‘MongoBleed’ bug being exploited
ID: 963d94f1-9d32-57df-b413-306a5884b2f7
STIX ID: report--963d94f1-9d32-57df-b413-306a5884b2f7
Feed Name: DataBreaches.Net
Threat Score
U.S. and Australian cyber agencies confirmed active exploitation of MongoDB’s CVE-2025-14847, for which exploit code was publicly released on December 25; MongoDB announced the flaw on December 15 and patched it on December 19. CISA has added the bug to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to patch by January 19.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
