NextGen Healthcare Mirth Connect
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS Vendor Equipment Vulnerabilities v3 8.3 NextGen Healthcare NextGen Healthcare Mirth Connect Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction of XML External Entity Reference Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-82583 NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. View CVE Details Affected Products NextGen Healthcare Mirth Connect Vendor: NextGen Healthcare Product Version: NextGen Healthcare Mirth Connect: <=v4.7.1 Product Status: known_affected Remediations Vendor fix NextGen recommends users update Mirth Connect v4.7.2 or later. Users can download the latest version from the NextGen Healthcare customer portal. Relevant CWE: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.3 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H 4.0 7.2 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N CVE-2026-78224 The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. View CVE Details Affected Products NextGen Healthcare Mirth Connect Vendor: NextGen Healthcare Product Version: NextGen Healthcare Mirth Conn
Details
Original advisory: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-82583 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78224 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-82578 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-82583: NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to exec…nvd
- highCVE-2026-82578: When XML batch processing is turned on and the XPath option is selected, the raw batch input g…nvd
- highCVE-2026-78224: The XSLT Transformer Step builds a bare TransformerFactory without the proper security options…nvd
Recent advisories for NextGen Healthcare Mirth
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerabilitycisa-kev · 2024-05-20
More from CISA Cybersecurity Advisories
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-11
- highCISA Adds Three Known Exploited Vulnerabilities to Catalog2026-09-11
- criticalST Engineering iDirect iQ-Series Terminals (Update A)2026-09-10
- criticalCISA Adds Two Known Exploited Vulnerabilities to Catalog2026-09-10
- criticalOrthanc DICOM Server2026-09-10