Security8 views

Critical MongoDB Vulnerability: Over 87,000 Servers Exposed Globally

A severe security vulnerability, identified as CVE-2025-14847 (dubbed MongoBleed), has left more than 87,000 MongoDB instances exposed worldwide. The flaw allows attackers to leak sensitive data directly from the system's memory.

Key Details:

  • The Risk: MongoBleed enables the theft of session tokens, API and cloud keys, internal logs, and plaintext credentials.
  • Global Impact: Over 87,000 servers are currently vulnerable.
  • Impact in Brazil: Approximately 2,000 compromised instances are located in Brazil.
  • Affected Versions: Users are urged to check their specific MongoDB version and apply official patches immediately to prevent data exfiltration.

How to Protect Your Data:

To mitigate the risk, administrators should update their MongoDB installations to the latest patched versions and audit their environments for unauthorized access. Detailed lists of affected and corrected versions are available via official security advisories and tech community hubs like TabNews.