Cyber Resilience
← All news
Confirmed

NextGen Healthcare Mirth Connect

Our takeCISA reports active exploitation of three vulnerabilities in NextGen Healthcare Mirth Connect <=4.7.1 that let attackers exfiltrate data or cause denial of service. Patch immediately if you run it; most teams on current builds or hosted alternatives are not affected.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of three vulnerabilities in NextGen Healthcare Mirth Connect <=v4.7.1 that can lead to data exfiltration or denial-of-service. Update to a fixed version immediately if you run self-hosted instances.
What this means for you — Lean IT orgs:If you run NextGen Mirth Connect on your own servers, update it right away — these flaws let attackers steal data or knock the system offline. Most smaller teams using a hosted service can ignore this.
What this means for you — MSP:CISA reports active exploitation in NextGen Mirth Connect <=v4.7.1 (CVEs allow data exfil or DoS). Check every client running self-hosted instances and push the update; hosted-service clients are unaffected.
What this means for you — Researcher:CISA confirms in-the-wild exploitation of CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 in NextGen Mirth Connect <=v4.7.1. Successful attacks can exfiltrate data or cause denial-of-service.