PatchSiren

NextGen Healthcare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH NextGen Healthcare CVE published 2026-09-11

CVE-2026-82583

CVE-2026-82583 debrief based on the supplied source corpus. The CVE record was published on 2026-09-11T15:17:06.510Z and has not been modified since then. This SQL injection vulnerability in NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allows authenticated users to execute arbitrary SQL, potentially leading to credential disclosure, arbitrary file write, and denial-of-service conditions. Def [truncated]

HIGH NextGen Healthcare CVE published 2026-09-11

CVE-2026-82578

This debrief provides an overview of CVE-2026-82578, a high-severity vulnerability with a CVSS score of 8.7. The vulnerability occurs when XML batch processing is turned on and the XPath option is selected, allowing for XXE injection and potential data exfiltration and denial-of-service attacks. Defenders and security teams should assess the potential impact and take necessary actions to prevent XXE injec [truncated]

HIGH NextGen Healthcare CVE published 2026-09-11

CVE-2026-78224

The CVE-2026-78224 vulnerability in NextGen Healthcare's Mirth Connect allows for XXE injection, potentially leading to data exfiltration and denial-of-service attacks. Defenders should assess exposure, prioritize remediation, and verify affected versions and scope. The vulnerability exists in the XSLT Transformer Step, which builds a bare TransformerFactory without proper security options. Affected syste [truncated]

Known exploited NextGen Healthcare CVE published 2024-05-20

CVE-2023-43208

CVE-2023-43208 affects NextGen Healthcare Mirth Connect and is identified by CISA as a Known Exploited Vulnerability as of 2024-05-20. CISA also marks this issue as associated with known ransomware campaign use. Because the supplied sources do not include a vendor patch advisory in the corpus, the safest defensive posture is to follow vendor mitigation guidance from the official NextGen Healthcare resourc [truncated]