>> All posts

CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution

The short version: Mirth Connect — NextGen Healthcare's widely used healthcare-data integration engine — has an unauthenticated remote code execution flaw (CVE-2023-43208). It scores 9.8, it's in CISA's KEV catalog, and it's associated with ransomware activity. It's also notable as an incomplete-patch follow-on to an earlier fix, so a previously "patched" server may still be vulnerable. If you run Mirth Connect below 4.4.1, patch now. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated RCE on a healthcare integration engine, KEV-listed
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~82.71% · 99.63th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2024-06-10; associated with known ransomware campaigns
Known exploited?Yes — exploited in the wild
Vulnerability typeCWE-78 OS command injection (via CWE-502 insecure deserialization) → unauthenticated RCE
Requires authenticated session?No — unauthenticated
AffectedNextGen Healthcare Mirth Connect before 4.4.1 (incomplete patch of CVE-2023-37679)
Fixed in4.4.1 (and later)

What you need to know

Mirth Connect routes and transforms clinical messages (HL7, and more) between healthcare systems — a piece of plumbing that touches sensitive data and connects many internal systems. CVE-2023-43208 lets an unauthenticated attacker trigger command execution on the server through an insecure data-handling path.

Two details make it matter more:

  • It's an incomplete patch. This flaw is a bypass of the earlier CVE-2023-37679 fix, so a server that was updated once may still be exposed unless it's on 4.4.1 or later.
  • It's a healthcare integration hub. Code execution here can reach protected health information and the many systems Mirth connects — exactly the profile ransomware operators target, which is why it carries a known-ransomware association in KEV.

How serious we see it

High — unauthenticated, network-reachable code execution on a system that brokers sensitive healthcare data, confirmed exploited and ransomware-associated.

The bounded, reassuring part is that it's narrow and fixable: it affects Mirth Connect below 4.4.1, the fix is published, and exposure is quick to determine. The catch is the incomplete-patch history — verify you're actually on 4.4.1 or later, not merely on a build you patched previously.

Recommendations

  1. Patch now. Upgrade Mirth Connect to 4.4.1 or later — earlier "patched" builds may still be vulnerable.
  2. Hunt. Review server and application logs for unexpected command execution and process activity around the exposure window.
  3. If compromised, respond. Rebuild the server, rotate credentials and integration secrets, and treat it as a potential PHI-exposure and ransomware precursor event per your incident process.
  4. Reduce exposure. Keep Mirth Connect's administrator and API interfaces off the public internet; restrict to trusted networks.
  5. Confirm your exposure first. Verify whether you run Mirth Connect and which version.

How BreachRisk sees it

BreachRisk discovers internet-facing Mirth Connect instances from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV and ransomware-associated. We detect and prioritize the exposed, affected server; the continuous outside-in view means a known-exploited healthcare hub is already mapped, so you can go straight to patch-and-verify.

References

See your cyber risk, proven.