CVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-05-20. EPSS: 82.7% chance of exploitation in the next 30 days.
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
Affected products
- NextGen Mirth Connect: before 4.4.1 (fixed in 4.4.1)
Published 2023-10-26. Last modified 2026-06-17.