More than 87,000 internet-exposed MongoDB instances could be compromised in ongoing intrusions exploiting the critical MongoBleed flaw, tracked as CVE-2025-14847, which originates from MongoDB Server's management of zlib library-processed network packets for lossless data compression and could be harnessed to facilitate secret exposure, reports BleepingComputer.
The U.S. had the most vulnerable servers at almost 20,000, followed by China, Germany, India, and France, according to data from Censys. Additional telemetry details from Wiz revealed that one or more MongoDB instances susceptible to MongoBleed were observed across 42% of visible systems.
Aside from the immediate patching of affected MongoDB versions, organizations have been urged by Recon InfoSec co-founder Eric Capuano to monitor for other indicators of compromise, as attackers could compromise available proof-of-concept exploit code with fraudulent client metadata.
MongoDB has already advised users who cannot upgrade to disable zlib compression instead.
The U.S. had the most vulnerable servers at almost 20,000, followed by China, Germany, India, and France, according to data from Censys. Additional telemetry details from Wiz revealed that one or more MongoDB instances susceptible to MongoBleed were observed across 42% of visible systems.
Aside from the immediate patching of affected MongoDB versions, organizations have been urged by Recon InfoSec co-founder Eric Capuano to monitor for other indicators of compromise, as attackers could compromise available proof-of-concept exploit code with fraudulent client metadata.
MongoDB has already advised users who cannot upgrade to disable zlib compression instead.
