On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- CISA added CVE-2026-86218 to the KEV catalog, a critical 10.0 CVSS vulnerability in N-able N-central allowing full server compromise without credentials.
- Two Windows vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are being actively exploited to gain administrative control over local systems.
- Orthanc DICOM servers prior to version 1.13.0 are vulnerable to integer overflows that can disable clinical imaging workflows.
- NextGen Healthcare Mirth Connect contains SQL injection and XML vulnerabilities that threaten HL7 messaging and patient data integrity.
- Manufacturers must verify that their third party service vendors have patched remote management tools to prevent supply chain breaches.
The industry faces high risk from active exploitation of Windows privilege escalation vulnerabilities and a critical 10.0 CVSS flaw in N-able N-central management tools. Manufacturers must also address supply chain risks in Orthanc DICOM servers and Mirth Connect middleware to prevent clinical workflow disruptions and data breaches.
This week, the Cybersecurity and Infrastructure Security Agency (CISA) added several high impact vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog. These additions include local privilege escalation flaws in Microsoft Windows that allow attackers to hijack update processes or trigger buffer overflows to gain full system control. For medical device manufacturers, these flaws represent a significant threat to diagnostic workstations and legacy imaging systems that may not receive frequent OS updates.
Furthermore, new advisories for Orthanc DICOM servers and NextGen Healthcare Mirth Connect highlight the ongoing risks within the medical device supply chain. Vulnerabilities in these widely used components can lead to memory corruption in imaging workflows or unauthorized database access via SQL injection. Regulatory and security leads should review their Software Bill of Materials (SBOM) to identify these components and plan immediate remediation to meet the FDA postmarket cybersecurity expectations.
In this brief
- Critical N-central Static Code Injection
- Windows Privilege Escalation and Buffer Overflow Flaws
- Orthanc DICOM Server Memory Corruption Risk
- Mirth Connect Middleware Vulnerabilities
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
These developments represent a direct threat to the availability and integrity of clinical systems. When core middleware like Mirth Connect or OS-level processes in Windows are compromised, the safety of patient data and the reliability of diagnostic tools are at risk. The FDA requires manufacturers to monitor these types of vulnerabilities and provide timely patches to maintain the cybersecurity posture of devices in the field.
Critical N-central Static Code Injection
CISA has added CVE-2026-86218 to the KEV catalog, highlighting a static code injection vulnerability in N-able N-central.
Windows Privilege Escalation and Buffer Overflow Flaws
Two Windows vulnerabilities have been identified as actively exploited in the wild.
Orthanc DICOM Server Memory Corruption Risk
A new advisory for the Orthanc DICOM server warns of an integer overflow vulnerability.
Mirth Connect Middleware Vulnerabilities
NextGen Healthcare Mirth Connect is facing SQL injection and XML vulnerabilities that could allow attackers to bypass security controls.
How Blue Goat Cyber Helps
Blue Goat Cyber assists medical device manufacturers in navigating the complex regulatory landscape by providing specialized penetration testing and cybersecurity strategy. Our team, led by Christian Espinosa, helps organizations identify supply chain risks and implement the security controls required for the FDA compliance. We offer a range of services tailored to the unique needs of the medical device industry.
FAQ
Get the next issue
Stay ahead of regulatory changes and emerging threats by subscribing to the Goat's Weekly.
