<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mirth Connect (&lt;=V4.7.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mirth-connect-v4.7.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 16:07:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mirth-connect-v4.7.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in NextGen Healthcare Mirth Connect</title><link>https://feed.craftedsignal.io/briefs/2026-09-mirth-connect-vulns/</link><pubDate>Thu, 10 Sep 2026 16:07:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mirth-connect-vulns/</guid><description>NextGen Healthcare Mirth Connect versions 4.7.1 and earlier contain three critical vulnerabilities including SQL injection and XML External Entity (XXE) injection flaws that allow for unauthorized data access and denial-of-service.</description><content:encoded><![CDATA[<p>NextGen Healthcare Mirth Connect versions 4.7.1 and earlier are affected by multiple high-severity vulnerabilities. These flaws include CVE-2026-82583, a SQL injection vulnerability within the Database Connector API that allows authenticated users to execute arbitrary SQL commands, potentially leading to credential disclosure, arbitrary file writes, and denial-of-service. Additionally, CVE-2026-78224 and CVE-2026-82578 involve improper restriction of XML External Entity (XXE) references within the XSLT Transformer step and XML batch processing, respectively. These XXE vulnerabilities enable unauthenticated attackers to perform data exfiltration and cause denial-of-service conditions. Mirth Connect is widely used in the healthcare sector for clinical data integration, making these flaws a significant target for actors seeking unauthorized access to sensitive medical data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can result in severe consequences, including the compromise of stored credentials for integrated systems, unauthorized access to sensitive patient data, arbitrary file system manipulation, and persistent denial-of-service of the Mirth Connect interface. These vulnerabilities affect healthcare organizations worldwide, potentially disrupting critical clinical workflows.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade NextGen Healthcare Mirth Connect to version 4.7.2 or later as recommended by the vendor.</li>
<li>Minimize network exposure by ensuring Mirth Connect instances are not directly accessible from the internet and are located behind firewalls.</li>
<li>Implement defense-in-depth strategies to isolate clinical systems from general business networks.</li>
<li>Monitor web server logs and database access logs for anomalous SQL queries or attempts to inject external entities into XML processing streams.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>medical-devices</category><category>vulnerability</category><category>cisa</category><category>ics</category></item></channel></rss>