MongoDB 2.x — End of Life

EOL High risk
EOL: Oct 31, 20164 releases in this series4 CVEs

MongoDB 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.6Apr 7, 2014Oct 31, 20162.6.12EOL
2.4Mar 18, 2013Mar 31, 20132.4.14EOL
2.2Aug 28, 2012Feb 28, 20142.2.7EOL
2.0Sep 11, 2011Mar 31, 20132.0.9EOL

CVEs affecting MongoDB 2.x (4)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-9753HIGH8.10.30%2.6The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9753HIGH8.10.30%2.2The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9753HIGH8.10.30%2.4The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9753HIGH8.10.30%2.0The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026

MongoDB 2.x is EOL — migrate to MongoDB 3.x

MongoDB 3.x is the next major release. Plan your upgrade before MongoDB 2.x stops receiving security patches.

See MongoDB 3.x

Frequently asked questions

Is MongoDB 2 end of life?

Yes. All MongoDB 2.x releases have reached end of life and no longer receive security patches. There are 4 known CVEs affecting MongoDB 2.x. Migrate to MongoDB 3.x as soon as possible.

What CVEs affect MongoDB 2?

There are 4 CVEs tracked for MongoDB 2.x. See the full list above with CVSS and EPSS scores.

What is the latest MongoDB 2 version?

The latest MongoDB 2.x patch release is 2.6.12, released on March 22, 2016. Always run the latest patch to benefit from all security fixes.

How to migrate from MongoDB 2 to MongoDB 3?

To migrate from MongoDB 2 to MongoDB 3: (1) review the official MongoDB 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run MongoDB 2 in production?

No. MongoDB 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA