logo

Merry Christmas Day! Have a MongoDB security incident.

ID: 4a797aa8-723d-5408-aebd-2fea2d2611f4

STIX ID: report--4a797aa8-723d-5408-aebd-2fea2d2611f4

Feed Name: DoublePulsar

Threat Score
85/100

Date Published: 2025-12-26

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A public proof-of-concept exploit called "MongoBleed" targets CVE-2025-14847 in MongoDB, enabling unauthenticated memory reads that can expose plaintext database passwords and cloud secrets; the vuln affects many versions going back roughly a decade, an estimated ~200k internet-facing instances exist, the exploit has been validated and published, and immediate patching of internet-facing assets is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.