Bleepingcomputer
Critical RCE Vulnerability Discovered in MongoDB
First seen 26 Dec 2025, 22:14 UTC
•


•45.3
Export
Article Content
Browse articles
MongoDB has identified a critical security vulnerability, tracked as CVE-2025-14847, that allows unauthenticated users to access uninitialized heap memory, potentially leading to remote code execution (RCE). This flaw affects multiple versions of MongoDB and MongoDB Server, and administrators are urged to apply patches immediately to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms
Critical PostgreSQL Vulnerability Exposes Databases to Remote Code Execution
AWS Strands Agents Tools Exposed to Multiple CVEs in 23 Days
Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks
Critical MongoDB Vulnerability Allows Arbitrary Code Execution