CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution
The short version: Mirth Connect — NextGen Healthcare's widely used healthcare-data integration engine — has an unauthenticated remote code execution flaw (CVE-2023-43208). It scores 9.8, it's in CISA's KEV catalog, and it's associated with ransomware activity. It's also notable as an incomplete-patch follow-on to an earlier fix, so a previously "patched" server may still be vulnerable. If you run Mirth Connect below 4.4.1, patch now. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — unauthenticated RCE on a healthcare integration engine, KEV-listed |
| CVSS v3.1 (NVD) | 9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | ~82.71% · 99.63th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation was due 2024-06-10; associated with known ransomware campaigns |
| Known exploited? | Yes — exploited in the wild |
| Vulnerability type | CWE-78 OS command injection (via CWE-502 insecure deserialization) → unauthenticated RCE |
| Requires authenticated session? | No — unauthenticated |
| Affected | NextGen Healthcare Mirth Connect before 4.4.1 (incomplete patch of CVE-2023-37679) |
| Fixed in | 4.4.1 (and later) |
What you need to know
Mirth Connect routes and transforms clinical messages (HL7, and more) between healthcare systems — a piece of plumbing that touches sensitive data and connects many internal systems. CVE-2023-43208 lets an unauthenticated attacker trigger command execution on the server through an insecure data-handling path.
Two details make it matter more:
- It's an incomplete patch. This flaw is a bypass of the earlier CVE-2023-37679 fix, so a server that was updated once may still be exposed unless it's on 4.4.1 or later.
- It's a healthcare integration hub. Code execution here can reach protected health information and the many systems Mirth connects — exactly the profile ransomware operators target, which is why it carries a known-ransomware association in KEV.
How serious we see it
High — unauthenticated, network-reachable code execution on a system that brokers sensitive healthcare data, confirmed exploited and ransomware-associated.
The bounded, reassuring part is that it's narrow and fixable: it affects Mirth Connect below 4.4.1, the fix is published, and exposure is quick to determine. The catch is the incomplete-patch history — verify you're actually on 4.4.1 or later, not merely on a build you patched previously.
Recommendations
- Patch now. Upgrade Mirth Connect to 4.4.1 or later — earlier "patched" builds may still be vulnerable.
- Hunt. Review server and application logs for unexpected command execution and process activity around the exposure window.
- If compromised, respond. Rebuild the server, rotate credentials and integration secrets, and treat it as a potential PHI-exposure and ransomware precursor event per your incident process.
- Reduce exposure. Keep Mirth Connect's administrator and API interfaces off the public internet; restrict to trusted networks.
- Confirm your exposure first. Verify whether you run Mirth Connect and which version.
How BreachRisk sees it
BreachRisk discovers internet-facing Mirth Connect instances from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV and ransomware-associated. We detect and prioritize the exposed, affected server; the continuous outside-in view means a known-exploited healthcare hub is already mapped, so you can go straight to patch-and-verify.