securityonline.info 8/18/2026, 2:50:49 PM · external

MongoDB patches 32 flaws, including critical CVE-2026-19001

MongoDB patches 32 flaws, including critical CVE-2026-19001
CyberSIXT Evidence Panel
Primary Source mongodb.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE critical alert discusses 32 disclosed security vulnerabilities in MongoDB, including the severe CVE-2026-19001, which has a CVSS score of 9.5 and allows for arbitrary code execution. None of the vulnerabilities are currently confirmed as actively exploited, but MongoDB has issued patches for all affected components. Key highlights include: 2 critical, 20 high, and 10 medium severity CVEs. The vulnerabilities primarily impact the MongoDB Server, BI Connector ODBC Driver, and other related tools. Administrators are advised to urgently apply security updates to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT