Patch released MongoDB rce patch-tuesday
MongoDB Server Vulnerability Wave Hits Document Databases
CVE Tools coverage
MongoDB Server has disclosed a new set of security issues affecting document databases, with fixes covering several MongoDB release lines (including 7.0, 8.0, 8.2, and 8.3). The advisories include CVE-2026-11933 (use-after-free in server-side JavaScript that can leak memory or crash when reachable by an authenticated user), CVE-2026-9740 (an unauthenticated denial-of-service crash via BSON validation recursion), CVE-2026-9750 and CVE-2026-9743 (authenticated and aggregation-related crash or incorrect-results scenarios). Because at least one bug can be triggered without authentication, upgrading to the provided fixed versions such as 8.0.26, 8.2.11, and 8.3.4 is a priority.