CVE-2026-78685: Le-Yan Medical Practice Management System

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.

Affected products

  • Le-Yan Medical Practice Management System: from 2.4.2.8, up to and including 2.5.1.9

Published 2026-08-25. Last modified 2026-08-26.