CVE-2025-14847 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
23
occurrences
First Seen
December 23, 2025
Last Seen
July 1, 2026

CVE-2025-14847 is a vulnerability tracked across 13 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed December 23, 2025; most recent activity July 1, 2026.

Related Threat Clusters

  • ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits

    A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…

    10 articles · Updated July 1, 2026
  • MongoBleed Vulnerability Exploited in the Wild

    The MongoBleed vulnerability, tracked as CVE-2025-14847 with a CVSS score of 8.7, is currently under active exploitation. Over 87,000 potentially vulnerable MongoDB instances have been identified worldwide, posing a…

    2 articles · Updated December 29, 2025
  • Critical Remote Code Execution Vulnerability in MongoDB (CVE-2025-14847)

    MongoDB has addressed a critical vulnerability, CVE-2025-14847, that allows unauthenticated remote attackers to execute arbitrary code on vulnerable servers. The flaw, with a CVSS score of 8.7, is linked to the server's…

    39 articles · Updated December 25, 2025
  • MongoBleed Vulnerability Exposes MongoDB Data to Attackers

    MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially…

    2 articles · Updated January 10, 2026
  • Critical MongoDB Vulnerability Exposes Sensitive Data via zlib Compression

    A critical vulnerability, tracked as CVE-2025-14847, has been identified in MongoDB's zlib compression implementation, allowing attackers to extract uninitialized heap memory from database servers without…

    6 articles · Updated December 24, 2025
  • Europe Launches GCVE Database for Cybersecurity Vulnerabilities

    The Global Cybersecurity Vulnerability Enumeration (GCVE) database has been launched in Europe to track IT security vulnerabilities and reduce reliance on U.S. systems. This initiative, accessible at db.gcve.eu, aims to…

    6 articles · Updated January 21, 2026
  • Critical RCE Vulnerability Discovered in MongoDB

    MongoDB has identified a critical security vulnerability, tracked as CVE-2025-14847, that allows unauthenticated users to access uninitialized heap memory, potentially leading to remote code execution (RCE). This flaw…

    4 articles · Updated December 26, 2025
  • MongoBleed (CVE-2025-14847) Exploits Unpatched MongoDB Servers

    CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after…

    2 articles · Updated December 31, 2025
  • Fortinet VPN Exploit Actively Targeted in Real-World Attacks

    Fortinet has reported that a five-year-old security vulnerability in its FortiOS SSL VPN software, identified as CVE-2020-12812, is being actively exploited in real-world attacks. This flaw allows attackers to bypass…

    4 articles · Updated December 26, 2025
  • Ransomware Recovery Costs Surge; Microsoft Addresses Critical Vulnerability

    The Sophos State of Ransomware in Enterprise 2025 report reveals that ransomware recovery costs for enterprises have exceeded $2 million, highlighting the ongoing challenge organizations face with this pervasive threat.…

    2 articles · Updated January 15, 2026

Recent Intelligence Reports

  • ChocoPoc malware delivered via trojanized exploits on GitHub — Bleepingcomputer · July 1, 2026
  • New ChocoPoC malware targets researchers via trojanized PoC exploits — Bleepingcomputer · July 1, 2026
  • ChocoPoc malware delivered via trojanized exploits on GitHub — Bleepingcomputer · July 1, 2026
  • New EU Vulnerability Platform GCVE Goes Live, Reducing Reliance on Global Systems — Thecyberexpress · January 21, 2026
  • CVE-2026-20805: Microsoft Fixes Actively Exploited Windows Desktop Manager Zero — Socprime · January 15, 2026
  • MongoBleed Vulnerability Allows Attackers to Read Data From MongoDB's Heap Memory — Infoq · January 10, 2026
  • MSP cybersecurity news digest, December 29, 2025 — Acronis · January 7, 2026
  • MSP cybersecurity news digest, December 29, 2025 — Acronis · January 7, 2026

CVSS v3.1 Breakdown