WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Active Exploitation of High-Severity Vulnerability Affecting MongoDB, “MongoBleed” (CVE-2025-14847)
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Active Exploitation of High-Severity Vulnerability Affecting MongoDB, “MongoBleed” (CVE-2025-14847)

Author: Alec Davison

Created: Tuesday, December 30, 2025 - 15:03

Categories:

(TLP:AMBER) A high-severity vulnerability affecting many versions of MongoDB Server is under active exploitation by threat actors. WaterISAC is sharing indicators of compromise (IOCs) shareable as TLP:AMBER. See PDF Attached.

The vulnerability has been designated with the “bleed” suffix due to its potential to leak memory or sensitive data, similar in nature to major vulnerabilities like Heartbleed and CitrixBleed. This is a highly dangerous vulnerability as no authentication is required, the vulnerability is in the default configuration, and sensitive data can leak incrementally…

READ MORE

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar