CVE-2025-14847Active Exploitation(mongodb / mongodb)

CRITICALCVSS 8.7 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch mongodb mongodb systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-19. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-130

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 28 mentions across 20 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 14 signals
  • General: 6 classified signals
  • Disclosure: 5 classified signals
  • Peaked 17d ago at 3 mentions (2026-02-01); latest day: 1
  • 28 total mentions across 20 days

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline28 mentions / 20d
01223Mentions · 2026-01-29: 2Mentions · 2026-01-31: 1Mentions · 2026-02-01: 3Mentions · 2026-02-04: 1Mentions · 2026-02-06: 3Mentions · 2026-02-10: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-20: 3Mentions · 2026-03-10: 1Mentions · 2026-03-28: 1Mentions · 2026-04-28: 2Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-05: 1Mentions · 2026-06-17: 1Mentions · 2026-07-08: 1Mentions · 2026-07-22: 1Mentions · 2026-08-06: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-02-20: 1Active Exploitation · 2026-01-29: 2Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-06: 2Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-06-17: 1Active Exploitation · 2026-08-06: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-01: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 2Technical Details · 2026-03-28: 1Technical Details · 2026-04-28: 2Technical Details · 2026-05-01: 1Technical Details · 2026-07-22: 101-2902-0102-0602-1702-2003-2805-0105-0507-0808-0610-08
Signal classification5 categories
Active Exploitation
1037.0%
General
622.2%
Disclosure
518.5%
PoC
311.1%
Patch
311.1%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-01-292
Active Exploitation2
2026-01-311
Active Exploitation1
2026-02-013
Disclosure2PoC1
2026-02-041
General1
2026-02-063
Active Exploitation2General1
2026-02-101
Disclosure1
2026-02-171
General1
2026-02-181
General1
2026-02-203
Active Exploitation1General1Patch1
2026-03-101
Patch1
2026-03-281
Active Exploitation1
2026-04-282
Disclosure1Patch1
2026-05-011
Disclosure1
2026-05-021
General1
2026-05-051
Active Exploitation1
2026-06-171
Active Exploitation1
2026-07-081
PoC1
2026-07-221
PoC1
2026-08-061
Active Exploitation1
Full discourse20 posts
  • reverseame@reverseame
    Disclosure

    MongoBleed: CVE-2025-14847 Memory Corruption in MongoDB. Your Database Talks Back https://phoenix.security/mongobleed-vulnerability-cve-2025-14847/

    Post summary

    The post announces the discovery of a memory corruption vulnerability (CVE-2025-14847) in MongoDB, directing readers to an external security article for details.

    112412.4K
    22.4K followersView on X
  • /r/netsec@_r_netsec
    General

    Mongobleed - CVE-2025-14847 https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb

    Post summary

    The text references MongoDB vulnerability CVE-2025-14847 and includes a link to an external article, but provides no further details about the vulnerability, PoC, exploitation status, or mitigation.

    03022638
    32.7K followersView on X
  • Alexander Steffanoff@xanderNLP
    General

    @brainage19 @ptr_to_joel CVE-2025-14847 aka MongoBleed

    Post summary

    The tweet merely references CVE-2025-14847 (MongoBleed) without any additional context or actionable information.

    10012407
    194 followersView on X
  • securelic@securelic
    Patch

    🚨 Critical MongoDB Vulnerability (MongoBleed) CVE-2025-14847 exposes sensitive data from MongoDB instances. Securelic explains the risk and the immediate fix. Stay ahead of attackers! 💻🔒 Read here https://securelic.com/blog/mongobleed-cve-2025-14847-critical-mongodb-data-leak-fix-securelic-qzrbss/cb8021cbf720c36fa6e87f177f676dcb #MongoDB #CyberSecurity #Securelic #Vulnerability #ai #hack

    Post summary

    The post highlights CVE‑2025‑14847, a critical MongoDB data leak, and points to an immediate fix available via the provided link.

    02010119
    4 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    PoC

    لباحثين رصدوا على الأقل 7 مستودعات PoC تنشر ChocoPoC، وكانت تستغل أسماء ثغرات مغرية مثل: 📍 FortiWeb CVE-2025-64446 📍 React2Shell CVE-2025-55182 📍 MongoBleed CVE-2025-14847 📍 PAN-OS CVE-2026-0257

    Post summary

    Researchers highlighted seven PoC repositories named ChocoPoC that host proof‑of‑concept exploits for several CVEs.

    10010141
    49.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2021-3156 3 - CVE-2025-14847 4 - CVE-2024-27867 5 - CVE-2024-11182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The message simply lists five trending CVE identifiers without providing any technical details, PoC, or exploitation context.

    000111.0K
    1.7K followersView on X
  • Blue Team News@blueteamsec1
    PoC

    MongoBleed: Critical MongoDB Vulnerability CVE-2025-14847 - custom Nuclei template (see below) designed to deterministically and safely detect if a MongoDB server is vulnerable to CVE-2025-14847, without exfiltrating data. http://dlvr.it/TQhZPR #cyber #threathunting #infosec

    Post summary

    The tweet shares a Nuclei template for detecting the critical MongoDB CVE‑2025‑14847 without data exfiltration.

    00002796
    54.7K followersView on X
  • InfoSecSherpa 🏔️@InfoSecSherpa
    Active Exploitation

    MongoBleed (CVE-2025-14847) Information Leak Vulnerability Exploited in the Wild by Peled Eldan and Erez Hasson from XM Cyber - December 31, 2025. https://cybersec.xmcyber.com/s/mongobleed-cve-2025-14847-information-leak-vulnerability-exploited-in-the-wild-24961 https://t.co/lCn4U8ECd7

    Post summary

    XM Cyber reports that the MongoBleed CVE-2025-14847 vulnerability was actively exploited in the wild; the post does not detail PoCs, exploits, or mitigation steps.

    01010417
    51.6K followersView on X
  • Open-source Projects@the_osps
    PoC

    mongobleed is a proof-of-concept exploit for CVE-2025-14847, an unauthenticated memory leak in MongoDB's zlib decompression. https://t.co/7mVmcTcPjY

    Post summary

    The tweet announces a PoC exploit called mongobleed that targets an unauthenticated memory leak in MongoDB’s zlib decompression (CVE-2025-14847).

    10000145
    1.2K followersView on X
  • Ankita Sinha@AnkitaSinh88200
    General

    MongoBleed is a reminder: Not every breach is sophisticated. Some are just: • open ports • no auth • sensitive data online Visibility ≠ security. 📝 Blog: https://medium.com/@ankisinha/mongobleed-cve-2025-14847-when-compression-becomes-a-data-exfiltration-vector-6fceaa9deecf #MongoBleed #DataBreach #CloudSecurity #Misconfiguration #CyberSecurity #MongoDB

    Post summary

    The tweet references MongoBleed CVE‑2025‑14847 as an example of simple misconfigurations but does not provide any technical details, exploit code, patch information, or evidence of active exploitation.

    0001065
    35 followersView on X
  • AJ King@ajkingio
    Active Exploitation

    MongoBleed (CVE-2025-14847) is actively being exploited against 200K+ internet-exposed MongoDB instances. But the real danger is internal — shadow databases become lateral movement gold. Network metadata analysis finds them regardless of port obfuscation.

    Post summary

    The post reports that CVE‑2025‑14847, known as MongoBleed, is actively exploited against over 200,000 internet‑exposed MongoDB instances, highlighting widespread real‑world attacks.

    0001064
    183 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Active Exploitation

    Critical MongoDB Flaw Exposes Heap Memory CVE-2025-14847 (“MongoBleed”) allows unauthenticated attackers to read uninitialized heap memory via malformed Zlib headers. Affected: MongoDB v3.6–8.2 Public exploits are live. https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2025-14847 #CVE202514847 #MongoBleed

    Post summary

    The post reports that MongoDB’s MongoBleed flaw (CVE-2025-14847) permits unauthenticated memory reads and that public exploits are actively in use, while offering no PoC, patch, or technical mitigation details.

    10000151
    42 followersView on X
  • @pedri77@pedri77

    MongoBleed (CVE-2025-14847) lets attackers remotely leak memory from unpatched MongoDB servers using zlib compression, without authentication. A critical vulnerability, CVE-2025-14847 (MongoBleed), was disclosed right a... https://f.mtr.cool/ecvuw9e9a9

    0000027
    2.1K followersView on X
  • Windows Forum@windowsforum
    Active Exploitation

    🚨 ABB Zenon IIoT ships with EOL MongoDB 4.2 and an actively exploited flaw. No normal patch—admins must swap the database or uninstall the service. Nothing says “enterprise” like DIY remediation. https://windowsforum.com/security-alerts.84/cve-2025-14847-leaves-abb-zenon-iiot-exposed-via-mongodb-4-2.441835/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #IndustrialCybersecurity #AbbZenon #Mongodb42 #Cve202514847 https://t.co/TqqfLWqmF7

    Post summary

    The post reports that ABB Zenon IIoT is exposed to an actively exploited flaw in legacy MongoDB 4.2, with no standard patch—requiring users to swap or remove the database.

    0000074
    1.3K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting MongoBleed (CVE-2025-14847) to extract credentials from MongoDB instances, then pivoting laterally across networks using compromised tokens. Runtime segmentation helps contain post-compromise movement between database tiers. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/mongobleed-vulnerability-2025-cve-2025-14847

    Post summary

    The analysis confirms that MongoBleed (CVE-2025-14847) is being actively exploited to steal credentials and lateral move within networks, underscoring the need for mitigation such as runtime segmentation.

    0000037
    1.9K followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-14847 MongoDB and MongoDB Server Improper Han @CISACyber https://www.rfr.bz/t5f5118

    Post summary

    CISA reports CVE‑2025‑14847 as actively exploited and has added it to the KEV catalog, but no PoC, exploit tool, patch, or detailed technical information is provided.

    000001.1K
    1.5K followersView on X
  • Yasir Raza@yasirrazahaidry
    Disclosure

    MongoBleed (CVE-2025-14847) exposes a memory corruption flaw in MongoDB. Your database talks back. Source: https://x.com/reverseame/status/2049004952131936275

    Post summary

    The tweet announces the discovery of a memory corruption vulnerability in MongoDB (CVE‑2025‑14847), providing minimal technical detail but no evidence of exploitation, patch, or PoC.

    00000944
    908 followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Patch

    Security alert: MongoBleed (CVE-2025-14847) — memory corruption in MongoDB. Read the analysis to understand impact, attack surface, and mitigation steps you should apply now: https://phoenix.security/mongobleed-vulnerability-cve-2025-14847/

    Post summary

    The alert highlights the MongoBleed vulnerability, providing a link to analysis and urging users to apply mitigation steps.

    00000599
    12 followersView on X
  • John Christly@christly
    Active Exploitation

    https://cybersec.xmcyber.com/s/mongobleed-cve-2025-14847-information-leak-vulnerability-exploited-in-the-wild-26206/1

    Post summary

    CVE‑2025‑14847 is an information‑leak vulnerability in MongoDB that has been reported as being exploited in the wild, with no PoC or exploit tool details provided.

    00000161
    437 followersView on X
  • Alexander Leonov@leonov_av
    Active Exploitation

    🚨 February Linux Patch Wednesday: 632 vulns (305 in Linux Kernel), 2 exploited in the wild - 💥 RCE Chromium (CVE-2026-2441), 🔓 MongoBleed in MongoDB (CVE-2025-14847) + 56 w/ public exploits. #LinuxPatchWednesday #Vulristics #Linux ➡️ https://t.me/avleonovcom/1634 https://t.co/e9lfQwsYLw

    Post summary

    The report highlights that two CVEs—CVE-2026-2441 (Chromium RCE) and CVE-2025-14847 (MongoBleed)—are actively exploited in the wild, with 56 public exploits mentioned, but it does not provide PoC, tool details, or patch information.

    0000062
    1.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---
Appmongodbmongodb---

Explore more