THREAT OPS › Threat News › CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE
CVE-2026-82583, CVE-2026-78224, CVE-2026-82578: NextGen Mirth Connect SQL injection and XXE
<p>Posted by Abhinav Agarwal on Sep 11</p>CISA has published ICSMA-26-253-01 for three vulnerabilities in NextGen<br /> Mirth Connect, a healthcare integration engine. Mirth Connect 4.7.1 and<br /> earlier are affected; 4.7.2 or later fixes all three.<br /> <br /> Mirth Connect was open source through 4.5.2; releases since 4.6 are closed<br /> source. The former public source and release history r
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-82583cve
- CVE-2026-78224cve
- CVE-2026-82578cve
Original source: https://seclists.org/oss-sec/2026/q3/715