MongoBleed - Vulnerability

Threat entity extracted from intelligence sources

Frequency
21
occurrences
First Seen
December 28, 2025
Last Seen
July 1, 2026

MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks.

MongoBleed is a vulnerability tracked across 12 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed December 28, 2025; most recent activity July 1, 2026.

Overview

MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks. The rapid adoption in the wild highlights its significance as an immediate risk to organizations deploying MongoDB, underscoring the need for review, patching, and monitoring of exposed instances.

Related Threat Clusters

  • ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits

    A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…

    10 articles · Updated July 1, 2026
  • MongoBleed Vulnerability Exploited in the Wild

    The MongoBleed vulnerability, tracked as CVE-2025-14847 with a CVSS score of 8.7, is currently under active exploitation. Over 87,000 potentially vulnerable MongoDB instances have been identified worldwide, posing a…

    2 articles · Updated December 29, 2025
  • MongoBleed Vulnerability Exposes MongoDB Data to Attackers

    MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially…

    2 articles · Updated January 10, 2026
  • MongoDB Flaw 'MongoBleed' Exploited Post-Patch Release

    A critical memory leak vulnerability in MongoDB, dubbed 'MongoBleed', has been exploited in the wild shortly after patches were released. Security teams are advised to restrict access to exposed MongoDB ports and review…

    2 articles · Updated December 29, 2025
  • MongoBleed (CVE-2025-14847) Exploits Unpatched MongoDB Servers

    CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after…

    2 articles · Updated December 31, 2025
  • Ransomware Recovery Costs Surge; Microsoft Addresses Critical Vulnerability

    The Sophos State of Ransomware in Enterprise 2025 report reveals that ransomware recovery costs for enterprises have exceeded $2 million, highlighting the ongoing challenge organizations face with this pervasive threat.…

    2 articles · Updated January 15, 2026
  • Over 70,000 MongoDB Servers Exposed to MongoBleed Vulnerability

    A critical vulnerability known as MongoBleed, tracked as CVE-2025-14847, affects over 74,000 MongoDB servers globally, allowing unauthenticated attackers to extract sensitive data from server memory. The flaw, linked to…

    6 articles · Updated December 30, 2025
  • Active Exploitation of MongoDB Vulnerability 'MongoBleed' Reported

    The US and Australian agencies have issued alerts regarding the active exploitation of the MongoDB vulnerability known as 'MongoBleed'. This vulnerability allows unauthenticated attackers with network access to probe…

    2 articles · Updated December 30, 2025
  • MongoDB Vulnerability Exploited by Hackers

    U.S. and Australian cyber agencies confirmed that hackers are exploiting a vulnerability in MongoDB data storage systems. The vulnerability, identified as CVE-2025-14847, was announced by MongoDB on December 15, 2025,…

    3 articles · Updated December 30, 2025
  • MongoBleed Vulnerability in MongoDB Exploited by Attackers

    A new vulnerability, dubbed MongoBleed, has been identified in MongoDB, allowing unauthenticated remote attackers to leak sensitive information from affected servers. The flaw has been exploited in attacks, with a…

    2 articles · Updated December 29, 2025

Recent Intelligence Reports

  • ChocoPoc malware delivered via trojanized exploits on GitHub — Bleepingcomputer · July 1, 2026
  • CVE-2026-20805: Microsoft Fixes Actively Exploited Windows Desktop Manager Zero — Socprime · January 15, 2026
  • MongoBleed Vulnerability Allows Attackers to Read Data From MongoDB's Heap Memory — Infoq · January 10, 2026
  • MSP cybersecurity news digest, December 29, 2025 — Acronis · January 7, 2026
  • MSP cybersecurity news digest, December 29, 2025 — Acronis · January 7, 2026
  • MongoBleed (CVE-2025-14847): the US, China, and the EU are among the top exploited GEOs — Securityaffairs · December 31, 2025
  • MongoBleed (CVE-2025-14847): the US, China, and the EU are among the top exploited GEOs — Securityaffairs.Co · December 31, 2025
  • Active MongoBleed exploitation warned by US, Australia — Scworld · December 30, 2025

Frequently asked questions

What is MongoBleed?

MongoBleed is a recently identified security flaw in MongoDB that is currently being actively exploited in real-world attacks.

Is MongoBleed still active?

The most recent intelligence report mentioning MongoBleed on ThreatCluster is dated July 1, 2026. Activity was first observed December 28, 2025, giving a tracked span from then to July 1, 2026.

What is MongoBleed associated with?

Across ThreatCluster reporting, MongoBleed most frequently co-occurs with Data Breach, Denial of Service, Malware, Ransomware, Trojan, among 12 tracked related entities.

What are the latest developments involving MongoBleed?

The most significant recent cluster is “ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits” (10 articles · Updated July 1, 2026). MongoBleed appears across 12 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on MongoBleed?

MongoBleed appears in 21 intelligence report mentions across 12 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown