PatchSiren

Mesalvo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Mesalvo CVE published 2026-05-20

CVE-2026-25602

CVE-2026-25602 is a vulnerability in Mesalvo's MEONA Client and MEONA Server, allowing users with specific administrative roles to send messages with content of their choosing from the server's address to a recipient of their choice. This issue can be used for social engineering and requires access to the hospital's internal network. The vulnerability affects versions 2024.10, 2025.04 (before 2025.04.24), [truncated]

HIGH Mesalvo CVE published 2026-05-20

CVE-2026-22315

CVE-2026-22315 was rejected by its CVE Numbering Authority. The CVE record was published on 2026-05-20T11:16:26.187Z and has not been modified since then. The NVD entry is currently Rejected.

HIGH Mesalvo CVE published 2026-05-20

CVE-2026-22314

CVE-2026-22314 is a Code Injection vulnerability in Mesalvo Meona Client Launcher Component and Meona Server Component. The vulnerability allows code execution on other users' systems. It affects Meona Client Launcher Component through 19.06.2020 15:11:49 and Meona Server Component through 2025.04 5+323020. The CVSS score is 7.9 with a HIGH severity. Defenders should prioritize verifying exposure, especia [truncated]