{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/care-everywhere-gateway-14.3.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-41939"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Care Everywhere Gateway (14.3.10)","WildFly (8.2.0.Final)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Care Everywhere","Red Hat"],"content_html":"\u003cp\u003eCare Everywhere Gateway version 14.3.10 utilizes a legacy version of the WildFly application server (8.2.0.Final) which contains hard-coded management credentials. This vulnerability allows remote, unauthenticated attackers to access the WildFly management interface, which is typically exposed on TCP port 20990. Once authenticated using the known default credentials, an attacker can leverage the application's deployment functionality to upload a malicious Web Application Archive (WAR) file. Successful execution of this file results in remote code execution (RCE) running with the privileges of the underlying Windows service account. This product reached end-of-life (EOL) in 2017, and no patches are expected for version 14.3.10, necessitating immediate network-level isolation or decommissioning of affected instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify instances of Care Everywhere Gateway exposing port 20990.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP connection to the WildFly management interface on port 20990.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the management interface using hard-coded default credentials.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the 'Deployments' management interface within the WildFly console.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a crafted, malicious .war file containing web shell or malware code.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the deployment of the uploaded .war file via the management console.\u003c/li\u003e\n\u003cli\u003eThe WildFly service extracts and executes the malicious application within the web server context.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution as the Windows system account running the service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative control over the affected Windows host running the Care Everywhere Gateway. Because the gateway often resides in sensitive infrastructure, this facilitates initial access into the internal network, potential exfiltration of sensitive medical or operational data, and lateral movement. Given the EOL status of the product, all identified instances represent a permanent high-risk security debt to the organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate all Care Everywhere Gateway 14.3.10 instances by blocking ingress and egress traffic to port 20990 at the perimeter firewall.\u003c/li\u003e\n\u003cli\u003eAudit network logs for any inbound traffic to port 20990 originating from unauthorized subnets or external IP addresses.\u003c/li\u003e\n\u003cli\u003ePlan for the immediate decommissioning of EOL software instances, as no security patches are available for CVE-2026-41939.\u003c/li\u003e\n\u003cli\u003eSearch for unauthorized .war files placed within the WildFly deployment directories on the host operating system.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T18:18:23Z","date_published":"2026-07-29T18:18:23Z","id":"https://feed.craftedsignal.io/briefs/2026-07-care-everywhere-gateway/","summary":"An unauthenticated remote code execution vulnerability exists in Care Everywhere Gateway 14.3.10 due to hard-coded credentials within the bundled WildFly 8.2.0.Final management interface.","title":"Hard-coded Credentials in Care Everywhere Gateway WildFly Management Interface","url":"https://feed.craftedsignal.io/briefs/2026-07-care-everywhere-gateway/"}],"language":"en","title":"CraftedSignal Threat Feed - Care Everywhere Gateway (14.3.10)","version":"https://jsonfeed.org/version/1.1"}