A critical vulnerability, CVE-2025-14847, known as MongoBleed, has been discovered in MongoDB, allowing unauthenticated remote attackers to read uninitialized heap memory from affected servers when zlib compression is enabled. This flaw exposes sensitive in-memory data such as credentials, session tokens, and application secrets, and is present across a wide range of MongoDB versions. The vulnerability is actively being exploited, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog and warning that over 80,000 servers are at risk. The attack requires no authentication or user interaction, making it a high-severity issue for organizations using MongoDB in cloud, SaaS, and enterprise environments.
The MongoBleed vulnerability has reportedly been linked to a major breach in Ubisoft's Rainbow Six Siege, where attackers exploited the flaw to manipulate in-game assets, resulting in the unauthorized distribution of billions of in-game credits and random moderation actions. Ubisoft responded by shutting down game servers and rolling back transactions, though the company has not officially confirmed MongoBleed as the root cause. The incident highlights the real-world impact of MongoDB vulnerabilities on high-profile applications and underscores the urgent need for organizations to apply mitigations and monitor for exploitation attempts.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-31, ProjectDiscovery updated its Nuclei template for CVE-2025-14847 to make detection deterministic and reduce false negatives. The maintainers said the template was validated against both vulnerable and patched hosts and noted exploitation had been observed in the wild.
On 2025-12-31, a Metasploit pull request introduced a scanner module for CVE-2025-14847 that can test for the flaw and extract leaked memory fragments for analysis. The release made exploitation and validation easier for security teams and potentially for attackers.
On 2025-12-30, Akamai released technical analysis and actionable detection guidance for MongoBleed, including queries and recommendations to identify vulnerable assets. The company emphasized immediate remediation because public exploits were available and active exploitation was ongoing.
By 2025-12-30, CISA had added CVE-2025-14847 to its Known Exploited Vulnerabilities catalog, reflecting confirmed in-the-wild exploitation. One report said more than 80,000 servers were facing active exploitation tied to the flaw.
By 2025-12-28, security reporting described MongoBleed as exploitable over the network without authentication and warned that mass attacks were likely as awareness increased. Subsequent reporting indicated public exploits were available and that more than 200,000 internet-exposed MongoDB instances were potentially at risk.
After the 2025-12-27 breach, Ubisoft responded by taking servers offline, rolling back unauthorized transactions, and telling players they would not be punished for spending illicitly issued credits. As of the reporting, the company had not published a full post-incident analysis or restoration timeline.
On 2025-12-27, Rainbow Six Siege suffered a major breach that allegedly exploited MongoBleed to gain backend access. Attackers distributed billions of in-game credits and items and manipulated moderation systems, with estimated impact exceeding $13 million in virtual currency.
Following disclosure, patched MongoDB releases were made available for affected versions, and defenders were advised to upgrade or disable zlib compression as a temporary mitigation. Guidance also recommended network segmentation and monitoring for signs of memory leakage or unusual traffic.
On 2025-12-19, CVE-2025-14847, dubbed MongoBleed, was disclosed as a critical unauthenticated memory disclosure flaw in MongoDB's handling of zlib-compressed messages. The issue affected a broad range of MongoDB versions and exposed sensitive memory contents such as credentials, tokens, and API keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceakamai.com
Open sourcesecurityonline.info
Open sourcebitsight.com
Open sourcerescana.com
Open sourcerescana.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.