MongoDB 2.x — End of Life
EOL High riskMongoDB 2.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 2.6 | Apr 7, 2014 | — | Oct 31, 2016 | 2.6.12 | EOL | |
| 2.4 | Mar 18, 2013 | — | Mar 31, 2013 | 2.4.14 | EOL | |
| 2.2 | Aug 28, 2012 | — | Feb 28, 2014 | 2.2.7 | EOL | |
| 2.0 | Sep 11, 2011 | — | Mar 31, 2013 | 2.0.9 | EOL |
CVEs affecting MongoDB 2.x (4)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 2.6 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 2.2 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 2.4 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 2.0 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
MongoDB 2.x is EOL — migrate to MongoDB 3.x
MongoDB 3.x is the next major release. Plan your upgrade before MongoDB 2.x stops receiving security patches.
Frequently asked questions
Is MongoDB 2 end of life?
Yes. All MongoDB 2.x releases have reached end of life and no longer receive security patches. There are 4 known CVEs affecting MongoDB 2.x. Migrate to MongoDB 3.x as soon as possible.
What CVEs affect MongoDB 2?
There are 4 CVEs tracked for MongoDB 2.x. See the full list above with CVSS and EPSS scores.
What is the latest MongoDB 2 version?
The latest MongoDB 2.x patch release is 2.6.12, released on March 22, 2016. Always run the latest patch to benefit from all security fixes.
How to migrate from MongoDB 2 to MongoDB 3?
To migrate from MongoDB 2 to MongoDB 3: (1) review the official MongoDB 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run MongoDB 2 in production?
No. MongoDB 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
