<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Core Server (8.2.x &lt; 8.2.12) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/core-server-8.2.x--8.2.12/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 24 Jul 2026 13:25:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/core-server-8.2.x--8.2.12/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Vulnerabilities in MongoDB Core Server and Compass</title><link>https://feed.craftedsignal.io/briefs/2026-07-mongodb-multi-vulnerabilities/</link><pubDate>Fri, 24 Jul 2026 13:25:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-mongodb-multi-vulnerabilities/</guid><description>Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.</description><content:encoded><![CDATA[<p>CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in MongoDB products, specifically affecting MongoDB Core Server and MongoDB Compass. These 26 distinct vulnerabilities, ranging from CVE-2026-13055 to CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, were initially detailed in MongoDB security bulletins on July 22, 2026. While no specific threat actor or active exploitation campaign has been identified, these flaws pose significant risks. Attackers could leverage these vulnerabilities to circumvent security policies, trigger denial-of-service (DoS) conditions, and exploit other unspecified security problems. Organizations using affected versions of MongoDB should prioritize applying the recommended patches to mitigate potential risks to their data and service availability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could lead to significant damage. An attacker could bypass existing security policies, potentially gaining unauthorized access to sensitive data or functionality within the MongoDB environment. The denial-of-service vulnerabilities could allow an attacker to disrupt the availability of MongoDB databases and applications relying on them, leading to operational outages and financial losses. Furthermore, the presence of &quot;unspecified security issues&quot; suggests that other, potentially more severe, impacts may be possible depending on the specific vulnerability and how it is exploited, including data corruption or unauthorized data modification.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Refer to the MongoDB security bulletins referenced in this brief (e.g., SERVER-123081, SERVER-124355) and apply all necessary patches to update affected MongoDB Core Server and Compass instances to the patched versions.</li>
<li>Patch CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737 on all affected MongoDB installations immediately.</li>
<li>Ensure that MongoDB Compass is updated to version 1.49.7 or later.</li>
<li>Upgrade MongoDB Core Server to versions 7.0.39 or later, 8.0.28 or later, 8.2.12 or later, or 8.3.7 or later, depending on the major version deployed.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>vulnerability</category><category>database</category><category>mongodb</category></item></channel></rss>