# MongoDB vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 5 MongoDB CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 8 tracked threat campaigns and 1 named threat actor.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 MongoDB CVEs published between 2026-08-15 and 2026-08-15. The busiest month was 2026-08 (5 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked MongoDB CVEs.

- [CVE-2026-81526](https://intel.threadlinqs.com/cve/CVE-2026-81526) — MEDIUM 6.5 · EPSS 0.2% · 2026-08-27
- [CVE-2026-81527](https://intel.threadlinqs.com/cve/CVE-2026-81527) — MEDIUM 6.5 · EPSS 0.2% · 2026-08-27
- [CVE-2026-81529](https://intel.threadlinqs.com/cve/CVE-2026-81529) — HIGH 7.1 · EPSS 0.2% · 2026-08-27
- [CVE-2026-81528](https://intel.threadlinqs.com/cve/CVE-2026-81528) — MEDIUM 5.4 · EPSS 0.2% · 2026-08-27
- [CVE-2026-81530](https://intel.threadlinqs.com/cve/CVE-2026-81530) — MEDIUM 5.6 · EPSS 0.1% · 2026-08-27

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 2 distinct MongoDB products are affected. The most frequently affected:

- C# Driver — 4 CVEs
- Rust Driver — 1 CVE

## Threat activity

8 tracked threat campaigns reference MongoDB products or exploit MongoDB CVEs:

- [Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000](https://intel.threadlinqs.com/threat/TL-2026-1834) — HIGH — 2026-08-03
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)](https://intel.threadlinqs.com/threat/TL-2026-0478) — CRITICAL — 2026-05-07
- [Node.js Windows Module Resolution Privilege Escalation via C:\\node_modules Planting (CVE-2026-0775, CVE-2026-0776)](https://intel.threadlinqs.com/threat/TL-2026-1548) — HIGH — 2026-04-08
- [MongoDB Database Extortion Campaign - 1,400+ Instances Ransacked](https://intel.threadlinqs.com/threat/TL-2026-0039) — HIGH — 2026-02-03
- [MongoDB Data Extortion Campaign - 1,400+ Databases Ransacked](https://intel.threadlinqs.com/threat/TL-2026-0023) — HIGH — 2026-02-02
- [Automated MongoDB Extortion Campaign Targeting Exposed Instances](https://intel.threadlinqs.com/threat/TL-2026-0006) — HIGH — 2026-02-02

## Threat actors targeting MongoDB

Named threat actors attributed to campaigns that involve MongoDB products or CVEs, with the number of linked campaigns:

- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1 campaign

## How to prioritise MongoDB patching

This order follows the data Threadlinqs holds for MongoDB, not a generic severity checklist:

- No MongoDB CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-81526](https://intel.threadlinqs.com/cve/CVE-2026-81526) (0.2%), [CVE-2026-81527](https://intel.threadlinqs.com/cve/CVE-2026-81527) (0.2%), [CVE-2026-81529](https://intel.threadlinqs.com/cve/CVE-2026-81529) (0.2%).
- 0 CVEs score Critical and 1 High on CVSS v3 (maximum 7.1, average 6.2); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/mongodb
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
