Nextgen
Nextgen Mirth Connect: vulnerabilities and CVEs
Nextgen Mirth Connect has 3 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.
CVEs3
Last 12 months1
Critical2
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43208 | Critical (9.8) | 83% | ⚠ Active exploitation | Oct 26, 2023 | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82583 | High (7.2) | 0.45% | — | Sep 11, 2026 | NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected… |
| CVE-2023-43208 | Critical (9.8) | 83% | ⚠ Active exploitation | Oct 26, 2023 | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679. |
| CVE-2023-37679 | Critical (9.8) | 99% | — | Aug 3, 2023 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.