Skip to content
Critical MongoDB Vulnerability Allows Server Crashes by Unauthenticated Attackers

Critical MongoDB Vulnerability Allows Server Crashes by Unauthenticated Attackers

First seen 5 Mar 2026, 14:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A high-severity vulnerability, CVE-2026-25611 (CVSS 7.5), has been identified in MongoDB, enabling unauthenticated attackers to crash exposed servers with minimal bandwidth. This flaw affects all MongoDB versions with compression enabled, including MongoDB Atlas, and over 207,000 instances are currently exposed according to Shodan data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 211d ago How this analysis works

Timeline

2026-02-10
CVE-2026-25611 published
2026-03-05
Vulnerability reported in Cybersecuritynews and GBHackers

More articles in this cluster (3)

Following this threat?

Track CVE-2026-25611 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed