As cited
Copy frozen at (site build).
vulnerabilities
High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect
Three high-severity vulnerabilities were discovered in NextGen Healthcare Mirth Connect, a healthcare integration platform that routes data between clinical systems. CVE-2026-82583 allows authenticated users to execute arbitrary SQL commands through the Database Connector application programming interface (API), exposing credentials and enabling denial-of-service attacks. CVE-2026-78224 and CVE-2026-82578 permit unauthenticated attackers to read local files and trigger denial-of-service conditions via XML External Entity injection. All three affect versions 4.7.1 and earlier; patches are available in version 4.7.2.
Why it matters: Healthcare organizations using Mirth Connect or products embedding it must update immediately, as these vulnerabilities expose databases, stored credentials, and patient data across connected clinical systems in the supply chain.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect
Three high-severity vulnerabilities were discovered in NextGen Healthcare Mirth Connect, a healthcare integration platform that routes data between clinical systems. CVE-2026-82583 allows authenticated users to execute arbitrary SQL commands through the Database Connector application programming interface (API), exposing credentials and enabling denial-of-service attacks. CVE-2026-78224 and CVE-2026-82578 permit unauthenticated attackers to read local files and trigger denial-of-service conditions via XML External Entity injection. All three affect versions 4.7.1 and earlier; patches are available in version 4.7.2.
Why it matters: Healthcare organizations using Mirth Connect or products embedding it must update immediately, as these vulnerabilities expose databases, stored credentials, and patient data across connected clinical systems in the supply chain.
- Source published
- First seen by Cybersecurity Tracker