MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks.
MongoBleed is a vulnerability tracked across 12 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed December 28, 2025; most recent activity July 1, 2026.
MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks. The rapid adoption in the wild highlights its significance as an immediate risk to organizations deploying MongoDB, underscoring the need for review, patching, and monitoring of exposed instances.
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
The MongoBleed vulnerability, tracked as CVE-2025-14847 with a CVSS score of 8.7, is currently under active exploitation. Over 87,000 potentially vulnerable MongoDB instances have been identified worldwide, posing a…
MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially…
A critical memory leak vulnerability in MongoDB, dubbed 'MongoBleed', has been exploited in the wild shortly after patches were released. Security teams are advised to restrict access to exposed MongoDB ports and review…
CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after…
The Sophos State of Ransomware in Enterprise 2025 report reveals that ransomware recovery costs for enterprises have exceeded $2 million, highlighting the ongoing challenge organizations face with this pervasive threat.…
A critical vulnerability known as MongoBleed, tracked as CVE-2025-14847, affects over 74,000 MongoDB servers globally, allowing unauthenticated attackers to extract sensitive data from server memory. The flaw, linked to…
The US and Australian agencies have issued alerts regarding the active exploitation of the MongoDB vulnerability known as 'MongoBleed'. This vulnerability allows unauthenticated attackers with network access to probe…
U.S. and Australian cyber agencies confirmed that hackers are exploiting a vulnerability in MongoDB data storage systems. The vulnerability, identified as CVE-2025-14847, was announced by MongoDB on December 15, 2025,…
A new vulnerability, dubbed MongoBleed, has been identified in MongoDB, allowing unauthenticated remote attackers to leak sensitive information from affected servers. The flaw has been exploited in attacks, with a…
MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks.
The most recent intelligence report mentioning MongoBleed on ThreatCluster is dated July 1, 2026. Activity was first observed December 28, 2025, giving a tracked span from then to July 1, 2026.
Across ThreatCluster reporting, MongoBleed most frequently co-occurs with Data Breach, Denial of Service, Malware, Ransomware, Trojan, among 12 tracked related entities.
The most significant recent cluster is “ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits” (10 articles · Updated July 1, 2026). MongoBleed appears across 12 threat clusters in total, listed above with sources.
MongoBleed appears in 21 intelligence report mentions across 12 deduplicated threat clusters, aggregated from 17,000+ monitored sources.