That “MongoBleed” Flaw? It’s Being Exploited Right Now.
A severe vulnerability in MongoDB Server, compared to Heartbleed, is now being actively exploited. The flaw, CVE-2025-14847, lets attackers read heap memory to steal passwords and keys. Patches are available, and CISA has added it to its must-fix list.