Threat Management, Threat Intelligence, Vulnerability Management, Patch/Configuration Management

Ongoing MongoBleed exploitation threatens over 87K servers

A digital chain breaking. Cybersecurity concept. Zeroes and ones. Cracking a secure system. Hacking technology. Security breach. Pen testing. Weakest link. Data breach.

More than 87,000 internet-exposed MongoDB instances could be compromised in ongoing intrusions exploiting the critical MongoBleed flaw, tracked as CVE-2025-14847, which originates from MongoDB Server's management of zlib library-processed network packets for lossless data compression and could be harnessed to facilitate secret exposure, reports BleepingComputer.

The U.S. had the most vulnerable servers at almost 20,000, followed by China, Germany, India, and France, according to data from Censys. Additional telemetry details from Wiz revealed that one or more MongoDB instances susceptible to MongoBleed were observed across 42% of visible systems.

Aside from the immediate patching of affected MongoDB versions, organizations have been urged by Recon InfoSec co-founder Eric Capuano to monitor for other indicators of compromise, as attackers could compromise available proof-of-concept exploit code with fraudulent client metadata.

MongoDB has already advised users who cannot upgrade to disable zlib compression instead.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds