So if you're using Atlas, check that your Cluster has auto upgraded already. If you're using 0.0.0.0/0, stop doing that and prefer a limited IP address range and even better, use VPC Peering or other security/network boundary features.
That is a ridiculous default.
It has been a minute since I used Mongo for production grade projects, so some things could have changed since then.
Not that it is fool proof, but if I am setting up the infrastructure I can probably control where the DB is deployed, so I would colocate it with the application servers on a local network or virtual local network, that is all I would be comfortable with.
When it says “authenticated exploit” it means you need to pass authentication first in order to trigger exploit whatever it may be.