ZoomEye finds 1,897,463 exposed MongoDB services
A ZoomEye scan on 2026-09-30 found 1,897,463 MongoDB services matching the database fingerprint. Queries for three CVE identifiers returned zero matches, which the authors call a measurement limitation rather than proof the flaws are absent.
- ZoomEye found 1,897,463 services matching the MongoDB fingerprint
- Queries for CVE-2026-88771, CVE-2026-76461 and CVE-2026-94127 returned zero matches
- An exposed data store needs only a connection, not a specific vulnerability
- Recommended fixes: enable auth, RBAC and restrict network access
Read next
Security