MongoDB patches 14 flaws enabling DoS and data exposure
CERT-FR issued an advisory for multiple vulnerabilities in MongoDB Core Server versions below 8.0.24, 8.2.10, 8.3.3, and 7.0.35 that allow remote denial of service and confidentiality breaches.
The French national CERT has published an advisory concerning multiple security vulnerabilities affecting MongoDB Core Server. The flaws impact versions 8.0.x prior to 8.0.24, 8.2.x prior to 8.2.10, 8.3.x prior to 8.3.3, and all versions prior to 7.0.35. The vulnerabilities enable attackers to conduct remote denial of service attacks and compromise data confidentiality.
MongoDB released patches on June 9, 2026, addressing fourteen distinct vulnerabilities tracked under CVE identifiers ranging from CVE-2026-9735 through CVE-2026-9754. The vendor published corresponding security bulletins in their JIRA tracking system for each vulnerability, spanning issue numbers SERVER-122207 through SERVER-126506.
Organizations running affected MongoDB Core Server versions should immediately consult MongoDB's security bulletins and apply the available patches to mitigate the risk of service disruption and unauthorized data access. The advisory emphasizes the criticality of addressing both the denial of service and confidentiality impact vectors.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0735/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free