[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-nextgen-mirth-connect-patches-three-high-severity-bugs":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},6259,"nextgen-mirth-connect-patches-three-high-severity-bugs","NextGen Mirth Connect Patches Three High Severity Bugs","NextGen Healthcare patched three high severity Mirth Connect flaws that let logged-in attackers steal data or crash the healthcare integration engine.","NextGen Healthcare's Mirth Connect has three high severity security holes, and one lets a logged-in user siphon off credentials for every connected system.\n\nCISA disclosed the flaws on September 10, 2026 in Mirth Connect versions 4.7.1 and earlier, the widely used open-source engine hospitals rely on to shuttle clinical data between systems. CVE-2026-82583 (CVSS 8.3) lets an authenticated user run arbitrary SQL through the Database Connector API, exposing stored credentials for linked systems, writing arbitrary files, and knocking the server offline. CVE-2026-78224 (CVSS 8.2) and CVE-2026-82578 (CVSS 7.5) are XML external entity flaws in the XSLT Transformer Step and the XML batch processing feature, both usable for data exfiltration or denial-of-service. NextGen fixed all three in version 4.7.2, available through its customer portal.\n\nMirth Connect sits at the plumbing layer of hospital IT, moving patient records between electronic health record systems, labs, and billing software, so a hole here has a bigger blast radius than a typical app bug. CISA says it has no evidence of active exploitation yet, but the SQL injection flaw only needs low-privilege authenticated access, a bar plenty of internal or contractor accounts already clear.\n\nXML external entity bugs are a known, decades-old vulnerability class, so finding two of them in an integration engine that hospitals still trust with live patient data in 2026 says a lot about how far healthcare software security lags behind the rest of the industry.","[\"healthcare\",\"vulnerabilities\",\"cisa\",\"mirth-connect\"]","2026-09-10T12:00:00.000Z","2026-09-10T16:10:13.812Z","2026-09-10T16:10:25.733Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Add the CVE identifiers (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) for the three flaws so readers can verify and track each vulnerability individually.","resolved","security",[32,33,34,35],"healthcare","vulnerabilities","cisa","mirth-connect",[37],{"name":38,"url":39},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-medical-advisories\u002Ficsma-26-253-01",0,{"sections":42},[43,48,51,56,61,66,71,75,80,85,90,95,100,105],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3480,"2026-09-11T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",628,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",336,"2026-09-11T00:56:21.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",153,"2026-09-09T15:12:32.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":47},"Science","science",98,{"name":76,"slug":77,"count":78,"latest_published_at":79},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":106,"slug":107,"count":108,"latest_published_at":109},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]