Mirth Connect (NextGen Connect Integration Engine) 4.4.0 and earlier — exploited remote command execution
Why this is on the list
Vendor-confirmed: affected range, remediation and fixed version come from the vendor or CNA advisory. Exploitation evidence names this product.
- CISA added this to its Known Exploited Vulnerabilities Catalog on 2024-05-20.
- CISA records it as having been used in ransomware campaigns.
Clinical integration engine routing HL7/ADT and lab interfaces between EHR, laboratory, imaging and billing systems. It handles ePHI in transit and sits between core clinical systems, so compromise affects both data confidentiality and interface availability.
Does this apply to your version?
An affected range is on record, derived from CISA's exploitation evidence rather than published by the product's vendor. Check your own release against it, or enter it in the lookup and Patient Protect will evaluate it for you.
Affected: <=4.4.0 · Fixed in 4.4.1
Check your versionWhat to do
Upgrade Mirth Connect to 4.4.1 or later. NextGen's 4.4.1 release documentation identifies Mirth Connect Core 4.4.0 and lower as affected by CVE-2023-43208 and states the XStream change shipped in 4.4.1 resolves it.
- Vendor
- NextGen Healthcare
- Product
- NextGen Connect Integration Engine
- Affected versions
- <=4.4.0
- Fixed in
- 4.4.1
- First published
- 2026-09-08
Where this comes from
5 sources- CISAPrimary government source
Confirms active exploitation · Informs severity
Vulnerability is exploited in the wild (CISA KEV listing)
Read the CISA record - VENDOR
Source assertion: affected_range:vendor
Read the VENDOR record - VENDOR
Source assertion: related_issue
Read the VENDOR record - VENDOR
Source assertion: vendor_fix
Read the VENDOR record - FIRSTSupporting intelligence
Informs severity
EPSS estimates a 83% probability that this vulnerability will be exploited in the next 30 days. It is a forecast about the vulnerability, not a statement about whether your installation is affected.
About EPSS
How this was assessed
- NextGen Healthcare's own release documentation for Mirth Connect 4.4.1 states that an unauthenticated remote command execution vulnerability (CVE-2023-43208) affects Mirth Connect Core 4.4.0 and lower, and that the XStream change shipped in 4.4.1 resolves it. CISA lists CVE-2023-43208 in its Known Exploited Vulnerabilities catalog, naming Mirth Connect, and records known ransomware use. Upgrade to 4.4.1 or later.
Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.
Do you run this?
Check your own version against the ledger — it may or may not fall inside the affected range.
Check your technology