MongoDB — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
61
occurrences
First Seen
December 16, 2025
Last Seen
August 22, 2026

MongoDB is a leading document-oriented NoSQL database platform used to store JSON-like data.

Overview

MongoDB is a leading document-oriented NoSQL database platform used to store JSON-like data. The MongoBleed vulnerability (CVE-2025-14847) allows attackers to read data from the database server's heap memory, creating a critical exposure for organizations running MongoDB; exploitation was reported as active in late December 2025 with broad global impact.

Related Threat Clusters

  • Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms

    Noma Labs has disclosed a critical vulnerability (CVE-2026-59726) in the Ruflo AI hosting platform, allowing unauthenticated attackers to execute arbitrary commands and take full control of AI agent environments. The…

    11 articles · Updated July 29, 2026
  • AWS Strands Agents Tools Exposed to Multiple CVEs in 23 Days

    Between July 15 and August 6, 2026, AWS Strands Agents Tools received four CVEs due to a design flaw exposing security-sensitive parameters as LLM-controllable inputs. The vulnerabilities include CVE-2026-15746…

    2 articles · Updated August 22, 2026
  • Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020

    CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP…

    15 articles · Updated June 17, 2026
  • Critical MongoDB Vulnerability Allows Arbitrary Code Execution

    A severe vulnerability in MongoDB, tracked as CVE-2026-8053, was published on May 12, 2026. This flaw enables attackers to execute arbitrary code on vulnerable database servers, potentially leading to complete system…

    2 articles · Updated May 14, 2026
  • PCPJack Malware Targets TeamPCP Victims for Credential Theft

    The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…

    11 articles · Updated May 7, 2026
  • Mass Database Extortion Campaign Targets Over 30,000 Systems

    A five-year study revealed that 30,515 exposed databases were targeted by ransom attacks, leading to significant damage even without payments. The Ransomnews Research Team's analysis from May 2021 to May 2026 found that…

    2 articles · Updated May 27, 2026
  • MongoBleed Vulnerability Exploited in the Wild

    The MongoBleed vulnerability, tracked as CVE-2025-14847 with a CVSS score of 8.7, is currently under active exploitation. Over 87,000 potentially vulnerable MongoDB instances have been identified worldwide, posing a…

    2 articles · Updated December 29, 2025
  • Critical MongoDB Vulnerability Allows Server Crashes by Unauthenticated Attackers

    A high-severity vulnerability, CVE-2026-25611 (CVSS 7.5), has been identified in MongoDB, enabling unauthenticated attackers to crash exposed servers with minimal bandwidth. This flaw affects all MongoDB versions with…

    3 articles · Updated March 5, 2026
  • Critical Remote Code Execution Vulnerability in MongoDB (CVE-2025-14847)

    MongoDB has addressed a critical vulnerability, CVE-2025-14847, that allows unauthenticated remote attackers to execute arbitrary code on vulnerable servers. The flaw, with a CVSS score of 8.7, is linked to the server's…

    39 articles · Updated December 25, 2025
  • MongoBleed Vulnerability Exposes MongoDB Data to Attackers

    MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially…

    2 articles · Updated January 10, 2026

Recent Intelligence Reports

  • AWS Strands Agents Tools Received Four CVEs in 23 Days — Cryptorank · August 22, 2026
  • AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause — Forkast.News · August 22, 2026
  • Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge — Csoonline · July 30, 2026
  • Huggingface Incident — www.ashimmahara.com · July 29, 2026
  • Most of the CVE-2026 — News.Ycombinator · June 17, 2026
  • Mass database extortion causes significant damage despite low payment rates — Feeds.Feedburner · May 27, 2026
  • Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code — Cybersecuritynews · May 14, 2026
  • Worm rubs out competitor's malware, then takes control — Theregister · May 8, 2026

CVSS v3.1 Breakdown