VORANT. Threat Intelligence Sign in Get the full feed

NextGen Mirth Connect flaws enable SQLi, XXE

routine vulnerability healthcare

Three vulnerabilities in NextGen Healthcare Mirth Connect ≤4.7.1 allow authenticated SQL injection and XXE attacks enabling data exfiltration and denial-of-service.

CISA has published an advisory covering three vulnerabilities in NextGen Healthcare's Mirth Connect (NextGen Connect), a widely used healthcare integration engine, affecting all versions up to and including 4.7.1. CVE-2026-82583 allows an authenticated user to execute arbitrary SQL via the Database Connector API, potentially disclosing stored credentials for connected systems, enabling arbitrary file writes, and causing denial-of-service. CVE-2026-78224 and CVE-2026-82578 are XML External Entity (XXE) injection vulnerabilities: the former stems from the XSLT Transformer Step building a TransformerFactory without secure settings, and the latter from XML batch processing with XPath enabled using a default, unrestricted XPath/JAXP configuration. Both XXE flaws can be exploited for data exfiltration and denial-of-service.

Mirth Connect is deployed worldwide across the Healthcare and Public Health sector to route and transform clinical data between systems, making these flaws relevant to hospitals and health IT integrators. NextGen has released version 4.7.2 to address all three issues, available via the customer portal. CISA states no known public exploitation has been reported at this time, and standard ICS network isolation, firewall segmentation, and VPN-based remote access guidance apply pending patch deployment. Defenders should prioritize patching to 4.7.2+ and audit database connector and XSLT/XML batch processing configurations for exposure.

Mentioned in this report

Vulnerabilities CVE-2026-78224CVE-2026-82578CVE-2026-82583

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free