logo

CRITICAL ALERT: Vulnerability in MongoDB product – MongoDB server leak

ID: 39743355-5e92-55b5-af8a-565a59ebbad4

STIX ID: report--39743355-5e92-55b5-af8a-565a59ebbad4

Feed Name: ASD's ACSC - Alerts RSS

Threat Score
90/100

Date Published: 2025-12-29

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

**Executive summary:** MongoDB has disclosed CVE-2025-14847, a critical unauthenticated vulnerability in its zlib implementation that can allow remote extraction of sensitive data from server memory; Australian authorities report active global exploitation. A broad range of MongoDB Server versions (including 3.6 through 8.2.x) are affected, and organisations are advised to apply patches immediately, review systems for unauthorised access, and consult MongoDB and OX Security guidance for mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.