← Vulnerability feed

Vulnerability record · CVE-2023-43208 · published 26 October 2023

CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution

Nextgen · Mirth Connect

NextGen Healthcare Mirth Connect before 4.4.1 is vulnerable to unauthenticated remote code execution. The flaw stems from an incomplete patch of CVE-2023-37679 and involves OS command injection and deserialization of untrusted data. It matters because a network-reachable, pre-auth RCE in an integration engine gives attackers full control of a system that often handles sensitive healthcare data.

9.8 CVSS 3.1 Critical CISA KEV since 20 May 2024 Known ransomware use EPSS 83% · top 0.3% CWE-78 · OS command injectionCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with a CVSS of 9.8, KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch.

What it is

NextGen Healthcare Mirth Connect before 4.4.1 is vulnerable to unauthenticated remote code execution. The flaw stems from an incomplete patch of CVE-2023-37679 and involves OS command injection and deserialization of untrusted data. It matters because a network-reachable, pre-auth RCE in an integration engine gives attackers full control of a system that often handles sensitive healthcare data.

Impact

An unauthenticated attacker can execute arbitrary code on the Mirth Connect server, leading to full compromise of confidentiality, integrity and availability. In practice this can mean data theft, lateral movement into connected clinical systems, and ransomware deployment.

Attack surface

The vulnerability is network-reachable with no privileges or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed Mirth Connect instance below 4.4.1 is directly in scope.

Exploitation

It is listed in CISA KEV with known ransomware campaign use, and EPSS gives a 30-day probability of about 0.83 (99.65th percentile). Public exploit references exist, so active exploitation should be assumed.

What to do

  • Upgrade Mirth Connect to version 4.4.1 or later immediately.
  • If patching is not possible, apply vendor mitigations or discontinue use of the product per CISA guidance.
  • Remove Mirth Connect from direct internet exposure and restrict access to trusted management networks.
  • Rotate credentials and secrets stored or used by the Mirth Connect server after patching.
  • Monitor for and investigate any signs of prior compromise before restoring normal operations.

Detection

  • Hunt for unexpected child processes spawned by the Mirth Connect Java process, especially shells and command interpreters.
  • Review Mirth Connect server logs and web access logs for anomalous requests or deserialization-related errors.
  • Monitor outbound network connections from Mirth Connect hosts to unfamiliar external addresses.
  • Check for newly created files, scheduled tasks or services on Mirth Connect hosts that are not part of normal operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-43208 to the Known Exploited Vulnerabilities catalog on 20 May 2024 as "NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43208 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-37679NextGen Mirth Connect command injection enables remote code executionNextGen Mirth Connect v4.3.0 contains a command injection flaw (CWE-77) that lets an unauthenticated remote attacker run arbitrary commands on the ho…EPSS 99%analysed8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2023-43208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.