CISA orders feds to patch MongoBleed flaw exploited in attacks
ID: 6ac703a3-155c-593a-bdf9-6126411ad17e
STIX ID: report--6ac703a3-155c-593a-bdf9-6126411ad17e
Feed Name: Bleeping Computer
CISA and multiple security vendors have warned of a critical MongoDB vulnerability (CVE-2025-14847, “MongoBleed”) in the zlib compression handling that allows unauthenticated remote memory leakage and theft of credentials, API/cloud keys, session tokens, logs, and PII; a public PoC exists, telemetry shows tens of thousands of potentially vulnerable Internet-exposed instances, and CISA has added the flaw to its known exploited vulnerabilities catalog and ordered federal agencies to patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
