Vendor
Multiple Critical Vulnerabilities in MongoDB Drivers and Core Server
3 CVEsMultiple vulnerabilities across MongoDB drivers and the Core Server identified on September 10-11, 2026, pose risks of remote denial-of-service, unauthorized data access, and integrity compromise.
Multiple Vulnerabilities in MongoDB
3 TTPsMultiple vulnerabilities in MongoDB allow remote attackers to achieve arbitrary code execution, bypass security controls, manipulate data, disclose sensitive information, or trigger a denial-of-service.
Detection of Destructive MongoDB Commands
1 rule 1 TTPDetection logic for identifying first-time client IP addresses issuing destructive MongoDB administrative commands often used in wipe-and-extort data destruction campaigns.
Multiple Vulnerabilities in MongoDB Core Server and Compass
2 TTPs 5 CVEs 52 IOCsNumerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.
Multiple Vulnerabilities Affect MongoDB
5 TTPsMultiple vulnerabilities in MongoDB allow an attacker to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or trigger a denial-of-service condition.
Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access
3 rules 4 TTPs 5 CVEsUnit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.
MongoDB Compass Vulnerability Allows File Manipulation and Potential Code Execution
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in MongoDB Compass to manipulate files and potentially execute arbitrary code.
MongoDB Timeseries Collection Vulnerability (CVE-2026-8053)
1 rule 1 CVEMongoDB published a security advisory to address CVE-2026-8053, an undefined behavior vulnerability when inserting data with duplicate field names into timeseries collections, affecting versions 5.0.0 through 8.3.1.
MongoDB Multiple Vulnerabilities
2 rules 4 TTPsAn authenticated remote attacker can exploit vulnerabilities in MongoDB to execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.
MongoDB Vulnerability Allows Local Code Execution
2 rules 2 TTPsA local attacker can exploit a vulnerability in MongoDB to execute arbitrary code, potentially leading to privilege escalation and system compromise.
AWS Identity API Access from Rare ASN Organizations
2 rules 1 TTPThis rule detects AWS identities with API traffic dominated by cloud-provider source AS organization labels, but also exhibit traffic from other AS organizations, potentially indicating credential reuse or pivoting.
Potential Database Dumping Activity on Linux
2 rules 1 TTPThis rule detects the use of database dumping utilities to exfiltrate data from a database on Linux systems, where attackers may attempt to dump the database to a file and then exfiltrate the file to a remote server.