Nextgen's vulnerability footprint centers on Mirth Connect, a healthcare integration platform widely deployed in clinical data exchange workflows. The observed exposure reflects the product's role as a message-processing intermediary, with recurring weakness classes including untrusted deserialization, command injection, and OS command injection that arise from handling external data streams and dynamic execution contexts. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextgen over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43208CRITICAL NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE- | Oct 26, 2023 | 9.8 | 97 | YES | YES |
CVE-2023-37679CRITICAL A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | Aug 3, 2023 | 9.8 | 91 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextgen.
Media articles that mention a CVE ID that affects a product developed by Nextgen — matched by CVE ID, not by vendor name.