Skip to main content

July 2026 Security Release

MongoDB Server versions 8.3.7, 8.0.28, 7.0.39, and Compass version 1.49.7 address each of the security advisories (“CVEs”) issued on the 21st of July

E
Written by Emily Tiang

At MongoDB, security is our top priority. Our security team continuously monitors for, and addresses, potential vulnerabilities and attempted misuse to ensure the integrity and safety of your environments. Below, we first share what you need to know to enhance your protection of your use of MongoDB products. We also explain how MongoDB thinks about patching predictability and security.

New Security Fixes


Today, we’re providing a set of updates that address 25 CVEs in MongoDB Server and 1 CVE in MongoDB Compass. MongoDB server customers should update to the latest release (MongoDB Server versions 8.3.7, 8.0.28, 7.0.39, and Compass version 1.49.7) that address each of the security advisories (“CVEs”) issued on the 21st of July.

There are no additional actions that need to be taken beyond patching.

Who is Affected and What Action is Suggested


For MongoDB Atlas Customers:

  • Please allow all maintenance to complete if you have deferred any. If you have not deferred any maintenance, you will already be on the latest versions.

For Enterprise Advanced/Self-Managed Customers:

  • Please update MongoDB Server to one of these versions which contain the patches. The patched versions are 8.3.7, 8.0.28, or 7.0.39.

For Compass Users:

  • Please update your MongoDB Compass to version 1.49.7.

How to Prioritize This Update


We recommend that all customers upgrade to a supported patched release:

  • All security advisories are listed below and are patched in our July release.

    • The patched versions are 8.3.7, 8.0.28, or 7.0.39.

As with any security patch, customers should consider their specific environment, access controls, and risk posture when assessing potential impact and deciding how quickly to apply these patches.

The action requested here is part of MongoDB's commitment to continuously improve our software and protect our customers.

List of Security Advisories ("CVEs")


The following are the security advisories (CVEs) included in the July 21st MongoDB Server and MongoDB Compass releases. Each is denoted with their “CVSS” score; please see our advice about CVSS scores.

  1. CVE-2026-13078: CVSS Score v3.1: 7.7/10, CVSS Score v4.0: 6.3/10

  2. CVE-2026-13077: CVSS Score v3.1: 7.1/10, CVSS Score v4.0: 7.1/10

  3. CVE-2026-13076: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  4. CVE-2026-13075: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  5. CVE-2026-13074: CVSS Score v3.1: 5.3/10, CVSS Score v4.0: 6.9/10

  6. CVE-2026-13073: CVSS Score v3.1: 4.3/10, CVSS Score v4.0: 5.3/10

  7. CVE-2026-13072: CVSS Score v3.1: 8.1/10, CVSS Score v4.0: 9.2/10

  8. CVE-2026-13071: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  9. CVE-2026-13070: CVSS Score v3.1: 5.3/10, CVSS Score v4.0: 6.0/10

  10. CVE-2026-13069: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  11. CVE-2026-13068: CVSS Score v3.1: 4.2/10, CVSS Score v4.0: 2.3/10

  12. CVE-2026-13067: CVSS Score v3.1: 6.3/10, CVSS Score v4.0: 7.2/10

  13. CVE-2026-13066: CVSS Score v3.1: 4.3/10, CVSS Score v4.0: 5.3/10

  14. CVE-2026-13065: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  15. CVE-2026-13064: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  16. CVE-2026-13063: CVSS Score v3.1: 4.3/10, CVSS Score v4.0: 5.1/10

  17. CVE-2026-13062: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  18. CVE-2026-13061: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  19. CVE-2026-13060: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 6.0/10

  20. CVE-2026-9737: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  21. CVE-2026-13059: CVSS Score v3.1: 8.1/10, CVSS Score v4.0: 8.6/10

  22. CVE-2026-13058: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  23. CVE-2026-13057: CVSS Score v3.1: 5.3/10, CVSS Score v4.0: 6.1/10

  24. CVE-2026-13056: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  25. CVE-2026-13055: CVSS Score v3.1: 6.5/10, CVSS Score v4.0: 7.1/10

  26. CVE-2026-14881: CVSS Score v3.1: 7.8/10, CVSS Score v4.0: 8.5/10


MongoDB’s Commitment to Customers’ Security and Ease of Software Updates


We have heard two messages clearly from customers as we, and the industry, increase our rate of security fixes in the Age of AI: (1) please make it easy for me to patch, and (2) please get security fixes out to me quickly. The 26 security fixes released on July 21st are part of our new, predictable cadence to release security fixes on a monthly basis.

When we need to urgently release a new version of MongoDB Server, we use well-practiced standard operating procedures to release minimalist changes (minimizing the number of changes over the software that customers are already using in Atlas or on-premises) that are thoroughly tested and carefully reviewed.

When we create our release plans, we are working backwards from the Atlas and MongoDB Enterprise Advanced customer experiences of having these patches land in your software stack. Not all security fixes are urgent (in fact, most are not) so we batch them up whenever the security and operational risk assessments support batching (hence the batch in the July 21st release). When the security risk is sufficiently high, we have demonstrated our commitment to moving quickly to protect customers (i.e., the June 11th release).

MongoDB Enterprise Advanced customers with robust internal automation, testing, and qualification are finding it straightforward to adapt to the increasing rate of security fixes in the industry. In Atlas, MongoDB takes care of the MongoDB Server deployments for you, minimizing the amount customers need to think about patching.

MongoDB is dedicated to protecting your data and ensuring the reliability of our services. We will continue to adopt the latest security and AI-based techniques to further harden our products. We thank you for your continued trust.

Did this answer your question?