A critical vulnerability in MongoDB, identified as CVE-2025-14847 and dubbed 'MongoBleed,' has been publicly disclosed, with a proof-of-concept (PoC) exploit released. The flaw resides in MongoDB's use of the zlib compression library, allowing unauthenticated attackers to send specially crafted messages that cause the server to leak fragments of its internal memory. This memory leak can expose sensitive data such as clear-text passwords, login keys, personal information, and security tokens, all without requiring authentication.
The impact of this vulnerability became immediately apparent when Ubisoft was forced to shut down its popular game, Rainbow Six Siege, after attackers exploited MongoBleed to compromise player accounts and internal systems. Thousands of gamers were locked out as a result, highlighting the real-world risks posed by the flaw. Security researchers have confirmed that multiple hacker groups are actively leveraging the PoC to target organizations using vulnerable MongoDB instances, emphasizing the urgent need for patching and mitigation.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the exploitation, Ubisoft shut down Rainbow Six Siege and its marketplace to contain the breach and began working to roll back fraudulent transactions. The outage was part of the company's incident response to the MongoBleed-related compromise.
Multiple hacker groups exploited MongoBleed to gain unauthorized access affecting Ubisoft's Rainbow Six Siege environment. The incident led to mass account bans and unbans, fraudulent distribution of in-game currency, and unlocking of cosmetic items for players.
A working proof-of-concept exploit for MongoBleed was released publicly, lowering the barrier to exploitation. Reporting said the PoC enabled unauthenticated attacks against vulnerable MongoDB deployments and was followed by a surge in attacks.
The MongoDB vulnerability dubbed MongoBleed, tracked as CVE-2025-14847, was publicly disclosed. The flaw was described as allowing unauthenticated attackers to access or drain memory from affected MongoDB instances via zlib-related behavior, creating denial-of-service and data-exposure risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.