NextGen Mirth Connect Vulnerabilities Expose Healthcare Systems

NextGen Mirth Connect Vulnerabilities Expose Healthcare Systems

First seen 10 Sep 2026, 17:45 UTC Bankinfosecuritywww.cisa.govwww.cve.org 60.6

Article Content

Browse articles
ThreatCluster

NextGen Healthcare's Mirth Connect integration engine has critical vulnerabilities that allow attackers to exfiltrate sensitive data and potentially disrupt services. The flaws include an authenticated SQL injection (CVE-2026-82583) and two XML parser vulnerabilities (CVE-2026-78224, CVE-2026-82578), all rated with CVSS scores between 7 and 8. These vulnerabilities could enable unauthorized access to administrator passwords and downstream systems, affecting healthcare organizations globally. The issues were reported by researcher Abhinav Agarwal and have been patched in version 4.7.2, released on August 5, 2026. Users are urged to update immediately to mitigate risks. The vulnerabilities impact Mirth Connect versions 4.7.1 and earlier, which are widely used in the healthcare sector for data exchange.

Key Points: • Critical vulnerabilities in Mirth Connect expose healthcare systems to data breaches. • Affected versions include Mirth Connect 4.7.1 and earlier; users must upgrade to 4.7.2. • Exploitation could lead to unauthorized access to sensitive healthcare data and denial-of-service.

Ask AI about this cluster

Timeline

2023-08-03
CVE-2023-37679 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-26
CVE-2023-43208 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
Patch released for Mirth Connect
NextGen Healthcare released version 4.7.2 to address critical vulnerabilities in Mirth Connect.
Bankinfosecurity
2026-09-10
CISA adds vulnerabilities to catalog
CISA added three high-severity vulnerabilities in Mirth Connect to its catalog, warning of potential exploitation.
CISA