The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to secure their systems against a high-severity MongoDB flaw that is actively being exploited in attacks. Dubbed MongoBleed and tracked as CVE-2025-14847, this vulnerability was patched on December 19, 2025, and it stems from how MongoDB Server processes network packets using the zlib library for data compression. Successful exploitation allows unauthenticated threat actors to remotely steal credentials and other sensitive data, including API and/or cloud keys, session tokens, internal logs, and personally identifiable information (PII), through low-complexity attacks that don't require user interaction. Elastic security researcher Joe Desimone has also released a proof-of-concept (PoC) exploit that leaks sensitive memory data when targeting unpatched hosts. On Monday, Internet security watchdog Shadowserver found over 74,000 Internet-exposed, potentially vulnerable MongoDB instances. Censys is also tracking over 87,000 IP addresses that have been fingerprinted as running possibly unpatched MongoDB versions. According to telemetry data from the cloud security platform Wiz, which also tagged the vulnerability as exploited in the wild over the weekend, the impact across the cloud environment appears significant, as 42% of visible systems "have at least one instance of MongoDB in a version vulnerable to CVE-2025-14847." CISA has now confirmed Wiz's report and has added the MongoBleed s...
CISA orders feds to patch MongoBleed flaw exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 30, 2025
·Updated
Affected Software
1 affected component
MongoDB MongoDB Server<2025-12-19
Frequently Asked Questions
1
What is the MongoBleed flaw mentioned in the article?
MongoBleed refers to a high-severity vulnerability in MongoDB, tracked as CVE-2025-14847, that is actively being exploited in cyber attacks.
2
Who issued the order to patch the MongoBleed flaw?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to secure their systems against the MongoBleed flaw.
3
What action has been taken regarding the MongoBleed vulnerability?
The MongoBleed vulnerability was patched on December 19, 2025.
4
What types of attacks are associated with the MongoBleed vulnerability?
MongoBleed is being actively exploited in attacks targeting systems that run vulnerable versions of MongoDB.
5
Which software is affected by the MongoBleed flaw?
The flaw affects MongoDB and specifically the MongoDB Server software.