On this page
In this issue
FDA & US regulatory
Letters, guidance, enforcement
CISA KEV & CVEs
Vulnerabilities in your SBOM
Standards & international
AAMI, ISO, IEC, EU MDCG
What to do this week
Concrete actions for security leads
Key Takeaways
- Multiple Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) present high to critical risks for embedded systems.
- A critical 10.0 CVSS score vulnerability in N-able N-central highlights major supply chain risks for remote monitoring.
- The Orthanc DICOM server and Mirth Connect middleware have significant flaws impacting clinical imaging and HL7 data flows.
- A Windows privilege escalation flaw (CVE-2026-81963) targets the update process on diagnostic workstations.
- A retrospective FDA recall for Abiomed blood pumps serves as a reminder of the long-term impact of firmware and software defects.
The primary development over the last 90 days is a cluster of critical Linux kernel vulnerabilities, including a remote code execution flaw in the TLS implementation. These issues, alongside a critical supply chain risk in N-able N-central management tools, demand immediate attention from manufacturers of connected imaging systems and patient monitors.
The last few months have seen a significant volume of vulnerabilities added to the CISA Known Exploited Vulnerabilities (KEV) catalog that directly impact the medical device ecosystem. While the regulatory landscape remains steady, the technical risk profile for devices running embedded Linux or relying on third party remote management tools has increased.
Security leads should treat KEV entries as a priority, because CISA lists them only when attackers are already exploiting the flaw. This recap covers the most significant items from the past 90 days to help teams prioritize their remediation work.
In this brief
- Critical Linux Kernel TLS Vulnerability
- Supply Chain Risk in Remote Management Tools
- Linux Kernel Memory and Race Condition Flaws
- Vulnerabilities in Medical Middleware and DICOM Servers
- Windows Privilege Escalation and Legacy Recalls
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For medical device manufacturers, these updates represent a shift in the threat landscape where standard infrastructure components like the Linux kernel and HL7 middleware are under active exploitation. Because the FDA considers CISA KEV entries as known risks, failure to address these items promptly can lead to regulatory delays or post-market enforcement actions.
Critical Linux Kernel TLS Vulnerability
CISA recently added CVE-2025-39682 to the KEV catalog.
Supply Chain Risk in Remote Management Tools
A critical vulnerability in N-able N-central, CVE-2026-86218, has been identified with a CVSS score of 10.0.
Linux Kernel Memory and Race Condition Flaws
Two other Linux kernel vulnerabilities have reached the KEV catalog.
Vulnerabilities in Medical Middleware and DICOM Servers
The Orthanc DICOM Server is affected by an integer overflow vulnerability.
Windows Privilege Escalation and Legacy Recalls
CVE-2026-81963 is a local privilege escalation flaw in Microsoft Windows.
How Blue Goat Cyber Helps
Blue Goat Cyber provides specialized penetration testing and regulatory support for medical device manufacturers. Our team focuses on identifying these types of kernel and middleware vulnerabilities before they result in a CISA KEV listing or an FDA recall. We help you navigate the complex requirements for SBOM management and vulnerability disclosure. For more information, visit our services page.
FAQ
Get the next issue
Stay informed on the latest medical device security risks by subscribing to Goat's Weekly.
