NextGen Healthcare Mirth Connect <=4.7.1 has three critical SQL injection and XXE vulnerabilities enabling data exfiltration, arbitrary file write, and denial of service; patch to v4.7.2+. An authenticated SQL injection in the Database Connector API allows arbitrary SQL execution, credential disclosure, and file write (CVE-2026-82583). Two unauthenticated XXE flaws in XSLT and XML batch processing enable data exfiltration and DoS (CVE-2026-78224, CVE-2026-82578). All require Mirth Connect upgrade to v4.7.2 or later.
xxe
3 posts
NextGen Healthcare Mirth Connect (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) Applied Systems Engineering ASE2000 V2 Communications Test Set (CVE-2018-1285, CVE-2026-18717) CISA published an ICS advisory for two vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37. CVE-2018-1285 is a critical XXE vulnerability in the bundled Apache log4net library that could allow arbitrary file read/write and outbound network requests. CVE-2026-18717 is a high-severity improper certificate validation flaw in the IEC 60870-5-104 TLS client that enables man-in-the-middle attacks. The vendor recommends upgrading to version 2.38, which remediates both issues.
Cyber Centre Daily Advisory Digest — 2026-08-20 (1 advisories) The Canadian Centre for Cyber Security issued a single advisory on August 20, 2026, summarizing multiple Cisco product vulnerabilities. Affected products include BroadWorks platform components, Crosswork network management tools, and Secure Workload, with fixes available in specific software versions or releases. The advisory references a blind XML External Entity Injection issue in BroadWorks but does not include a CVE number, CVSS score, or exploitation details in the provided text.