Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    ⌘K
    The Goat's Weekly

    Medical Device Cybersecurity News: Week of Monday, September 14, 2026

    The industry faces high risk from active exploitation of Windows privilege escalation vulnerabilities and a critical 10.

    Hero image for Medical Device Cybersecurity News: Week of Monday, September 14, 2026
    Week of September 14, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    6 min read1,211 words

    Key Takeaways

    • CISA added CVE-2026-86218 to the KEV catalog, a critical 10.0 CVSS vulnerability in N-able N-central allowing full server compromise without credentials.
    • Two Windows vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are being actively exploited to gain administrative control over local systems.
    • Orthanc DICOM servers prior to version 1.13.0 are vulnerable to integer overflows that can disable clinical imaging workflows.
    • NextGen Healthcare Mirth Connect contains SQL injection and XML vulnerabilities that threaten HL7 messaging and patient data integrity.
    • Manufacturers must verify that their third party service vendors have patched remote management tools to prevent supply chain breaches.
    Direct Answer

    The industry faces high risk from active exploitation of Windows privilege escalation vulnerabilities and a critical 10.0 CVSS flaw in N-able N-central management tools. Manufacturers must also address supply chain risks in Orthanc DICOM servers and Mirth Connect middleware to prevent clinical workflow disruptions and data breaches.

    This week, the Cybersecurity and Infrastructure Security Agency (CISA) added several high impact vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog. These additions include local privilege escalation flaws in Microsoft Windows that allow attackers to hijack update processes or trigger buffer overflows to gain full system control. For medical device manufacturers, these flaws represent a significant threat to diagnostic workstations and legacy imaging systems that may not receive frequent OS updates.

    Furthermore, new advisories for Orthanc DICOM servers and NextGen Healthcare Mirth Connect highlight the ongoing risks within the medical device supply chain. Vulnerabilities in these widely used components can lead to memory corruption in imaging workflows or unauthorized database access via SQL injection. Regulatory and security leads should review their Software Bill of Materials (SBOM) to identify these components and plan immediate remediation to meet the FDA postmarket cybersecurity expectations.

    In this brief

    Why This Matters

    These developments represent a direct threat to the availability and integrity of clinical systems. When core middleware like Mirth Connect or OS-level processes in Windows are compromised, the safety of patient data and the reliability of diagnostic tools are at risk. The FDA requires manufacturers to monitor these types of vulnerabilities and provide timely patches to maintain the cybersecurity posture of devices in the field.

    Critical N-central Static Code Injection

    Critical

    CISA has added CVE-2026-86218 to the KEV catalog, highlighting a static code injection vulnerability in N-able N-central.

    Windows Privilege Escalation and Buffer Overflow Flaws

    Critical

    Two Windows vulnerabilities have been identified as actively exploited in the wild.

    Orthanc DICOM Server Memory Corruption Risk

    High

    A new advisory for the Orthanc DICOM server warns of an integer overflow vulnerability.

    Mirth Connect Middleware Vulnerabilities

    Critical

    NextGen Healthcare Mirth Connect is facing SQL injection and XML vulnerabilities that could allow attackers to bypass security controls.

    ## What to do this week * Audit your SBOM for Orthanc versions prior to 1.13.0 and schedule a binary update for all affected diagnostic tools. * Confirm with your IT department and third party managed service providers that N-able N-central instances are patched against CVE-2026-86218. * Review your clinical workstation update schedule to ensure that the latest Windows security patches for CVE-2026-81963 and CVE-2026-85880 are applied.

    How Blue Goat Cyber Helps

    Blue Goat Cyber assists medical device manufacturers in navigating the complex regulatory landscape by providing specialized penetration testing and cybersecurity strategy. Our team, led by Christian Espinosa, helps organizations identify supply chain risks and implement the security controls required for the FDA compliance. We offer a range of services tailored to the unique needs of the medical device industry.

    FAQ

    Get the next issue

    Stay ahead of regulatory changes and emerging threats by subscribing to the Goat's Weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.