CISA Warns of Critical SQL Injection and XXE Vulnerabilities in NextGen Healthcare Mirth Connect
The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities in NextGen Healthcare Mirth Connect to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-82583 is a SQL injection flaw allowing authenticated users to execute arbitrary SQL via the Database Connector API, potentially leading to credential disclosure, arbitrary file writes, and denial-of-service. CVE-2026-78224 and CVE-2026-82578 are XML External Entity (XXE) injection vulnerabilities arising from insecure TransformerFactory and XPath configurations, respectively. Both XXE flaws can be exploited unauthenticated and may result in data exfiltration and denial-of-service conditions. All three affect Mirth Connect versions 4.7.1 and earlier. NextGen Healthcare recommends upgrading to v4.7.2 or later.