{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/core-server-8.2.x--8.2.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-14881"},{"cvss":6.5,"id":"CVE-2026-13056"},{"cvss":4.3,"id":"CVE-2026-13063"},{"cvss":5.3,"id":"CVE-2026-13070"},{"cvss":4.3,"id":"CVE-2026-13073"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Compass (\u003c 1.49.7)","Core Server (7.0.x \u003c 7.0.39)","Core Server (8.0.x \u003c 8.0.28)","Core Server (8.2.x \u003c 8.2.12)","Core Server (8.3.x \u003c 8.3.7)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","database","mongodb"],"_cs_type":"threat","_cs_vendors":["MongoDB"],"content_html":"\u003cp\u003eCERT-FR has issued an advisory regarding multiple vulnerabilities discovered in MongoDB products, specifically affecting MongoDB Core Server and MongoDB Compass. These 26 distinct vulnerabilities, ranging from CVE-2026-13055 to CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, were initially detailed in MongoDB security bulletins on July 22, 2026. While no specific threat actor or active exploitation campaign has been identified, these flaws pose significant risks. Attackers could leverage these vulnerabilities to circumvent security policies, trigger denial-of-service (DoS) conditions, and exploit other unspecified security problems. Organizations using affected versions of MongoDB should prioritize applying the recommended patches to mitigate potential risks to their data and service availability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to significant damage. An attacker could bypass existing security policies, potentially gaining unauthorized access to sensitive data or functionality within the MongoDB environment. The denial-of-service vulnerabilities could allow an attacker to disrupt the availability of MongoDB databases and applications relying on them, leading to operational outages and financial losses. Furthermore, the presence of \u0026quot;unspecified security issues\u0026quot; suggests that other, potentially more severe, impacts may be possible depending on the specific vulnerability and how it is exploited, including data corruption or unauthorized data modification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefer to the MongoDB security bulletins referenced in this brief (e.g., SERVER-123081, SERVER-124355) and apply all necessary patches to update affected MongoDB Core Server and Compass instances to the patched versions.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737 on all affected MongoDB installations immediately.\u003c/li\u003e\n\u003cli\u003eEnsure that MongoDB Compass is updated to version 1.49.7 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade MongoDB Core Server to versions 7.0.39 or later, 8.0.28 or later, 8.2.12 or later, or 8.3.7 or later, depending on the major version deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T13:25:53Z","date_published":"2026-07-24T13:25:53Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mongodb-multi-vulnerabilities/","summary":"Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.","title":"Multiple Vulnerabilities in MongoDB Core Server and Compass","url":"https://feed.craftedsignal.io/briefs/2026-07-mongodb-multi-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Core Server (8.2.x \u003c 8.2.12)","version":"https://jsonfeed.org/version/1.1"}