logo

MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know

ID: 80423857-7761-5155-b6b8-d27bb9e46461

STIX ID: report--80423857-7761-5155-b6b8-d27bb9e46461

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2025-12-28

Date Updated: 2026-05-01

...
...

CVE-2025-14847 (MongoBleed) is a high-severity unauthenticated info-leak in MongoDB’s zlib decompression that can expose in-memory data to remote attackers; it affects many supported and legacy MongoDB versions, has had public exploits and confirmed internet-exposed instances, and requires immediate patching or disabling zlib compression and network exposure mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.