On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- CISA added two N-able N-central authentication bypass vulnerabilities (CVE-2026-18556 and CVE-2026-18577) to the KEV catalog, posing a direct threat to remote device management.
- An unencrypted data vulnerability in Apache Tomcat (CVE-2026-34486) is being actively exploited, putting sensitive clinical information in PACS and portals at risk.
- Thermo Fisher Applied Biosystems Genetic Analyzers face a vulnerability that allows remote actors to manipulate raw genomic data.
- Medixant RadiAnt DICOM viewers are susceptible to out of bounds write vulnerabilities that can cause application crashes during image review.
- the FDA expects manufacturers to verify if these vulnerable components reside in their support supply chains and to initiate rapid patching.
CISA has added multiple vulnerabilities affecting N-able N-central and Apache Tomcat to the Known Exploited Vulnerabilities catalog, signaling active exploitation of remote monitoring and web server components. Additionally, new advisories for Medixant RadiAnt DICOM and Thermo Fisher genetic analyzers highlight risks to diagnostic data integrity and clinical workflows.
This week, the focus shifts to the software supply chain and remote management tools used to maintain medical device fleets. The addition of authentication bypass vulnerabilities to the CISA Known Exploited Vulnerabilities (KEV) catalog emphasizes that attackers are successfully targeting the administrative channels used by manufacturers to support Class II and III systems.
Security leads must also contend with vulnerabilities in specialized diagnostic software. From genomic data manipulation in laboratory sequencers to denial of service risks in DICOM viewers, the threat landscape covers both the integrity of clinical results and the availability of critical imaging services. As the FDA increases scrutiny on postmarket management, rapid identification of these components within the medical device ecosystem is mandatory.
In this brief
- Critical Authentication Bypasses in N-able N-central
- Active Exploitation of Apache Tomcat Data Encryption Flaw
- Data Integrity Risks in Thermo Fisher Genetic Analyzers
- Medixant RadiAnt DICOM Out of Bounds Write
- Why This Matters
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For medical device manufacturers, these vulnerabilities represent a breakdown in the secure management and transmission of patient data. When remote monitoring tools or web servers are compromised, the entire fleet of connected devices becomes accessible to unauthorized actors. This can lead to unauthorized configuration changes, data exfiltration, or the corruption of diagnostic results, directly impacting patient safety and regulatory standing.
Critical Authentication Bypasses in N-able N-central
CISA has added two high-severity vulnerabilities, CVE-2026-18556 and CVE-2026-18577, to the KEV catalog.
Active Exploitation of Apache Tomcat Data Encryption Flaw
Apache Tomcat CVE-2026-34486 is now listed in the CISA KEV catalog.
Data Integrity Risks in Thermo Fisher Genetic Analyzers
A new advisory highlights a vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers that could allow remote actors to manipulate raw genomic data files.
Medixant RadiAnt DICOM Out of Bounds Write
Medixant RadiAnt DICOM viewers are affected by an out of bounds write vulnerability.
How Blue Goat Cyber Helps
Blue Goat Cyber assists medical device manufacturers in navigating the complexities of postmarket cybersecurity requirements. Our team, led by Christian Espinosa, provides expert guidance on vulnerability management, SBOM analysis, and regulatory alignment. We help ensure that your devices remain secure and compliant throughout their entire lifecycle. To learn more about our approach, visit our services page.
FAQ
Get the next issue
Subscribe to stay informed on the latest regulatory and security developments for medical devices at Goat's Weekly.
