VYPR
Vypr IntelligenceAI-generatedSep 11, 2026· 24 CVEs

24 Vulnerabilities Disclosed Across Multiple Products: Authentication, Injection, and Credential Flaws Exposed

24 vulnerabilities disclosed across Cisagov Csaf, Mirth Connect, Orthanc, and AVEVA systems, featuring authentication bypass, injection flaws, and credential mismanagement.

Key findings

  • A batch of 24 vulnerabilities disclosed between Sep 8-11, 2026, impacts Cisagov Csaf, Mirth Connect, Orthanc DICOM Server, and AVEVA Pipeline Integrity Monitor.
  • Flaws include hardcoded credentials, weak hashing, authentication bypass, and insecure direct object references across multiple products.
  • Injection vulnerabilities like SQLi, command injection, XXE, and XSS are present, alongside memory corruption and open redirect flaws.
  • High-severity issues in Mirth Connect and camera systems could lead to credential theft, data exfiltration, and device control.
  • Coordinated advisories from CISA highlight affected versions and potential impacts, urging prompt patching.

On September 11, 2026, a significant batch of 24 vulnerabilities was disclosed across multiple products from various vendors, with a disclosure window spanning from September 8th to September 11th, 2026. These vulnerabilities encompass a wide range of security weaknesses, including authentication bypass, insecure direct object references, cross-site scripting (XSS), and remote code execution (RCE), affecting products such as Cisagov's Csaf, NextGen Healthcare's Mirth Connect, Orthanc DICOM Server, and AVEVA's Pipeline Integrity Monitor. The sheer volume and varied nature of these flaws highlight a broad set of security concerns for users of these critical systems.

Several vulnerabilities center on insecure handling of credentials and authentication mechanisms. CVE-2026-90456 and CVE-2026-90451 describe instances where example configuration files ship with hardcoded, publicly known administrative passwords or secret values, posing a severe risk if not properly regenerated during setup. CVE-2026-90457 details a weak hashing algorithm for administrative passwords, with the resulting hash file having overly permissive read permissions. CVE-2026-90449 highlights a misconfiguration where a bundled third-party administrative interface is forwarded directly by the reverse proxy without its own authentication, bypassing gateway security. Additionally, CVE-2026-90452 points to a critical flaw where the reverse proxy fails to verify the identity provider's server certificate, opening the door for man-in-the-middle attacks. CVE-2026-90448 and CVE-2026-90446 involve API endpoints that accept user-supplied values, allowing attackers to manipulate backend requests, potentially leading to data compromise or unauthorized access.

Cross-site scripting (XSS) and related injection vulnerabilities are also prominent in this batch. CVE-2026-90444 describes an interface that accepts user-controlled filenames with shell metacharacters, leading to command injection when processed by an automated system. CVE-2026-90445 details an archive upload handler that extracts files without validating paths, enabling directory traversal attacks. CVE-2026-90453 highlights an open redirect vulnerability in a file-upload handler, allowing attackers to redirect authenticated users to arbitrary external sites. CVE-2026-81824, affecting AVEVA Pipeline Integrity Monitor, allows arbitrary JavaScript execution in a user's browser session via a crafted link. Furthermore, CVE-2026-87020 involves an integer overflow leading to a heap out-of-bounds write when processing specially crafted PNG images in Orthanc DICOM Server. CVE-2026-82583 and CVE-2026-78224, affecting NextGen Mirth Connect, are XML External Entity (XXE) injection vulnerabilities that can lead to data exfiltration and denial-of-service.

Several high-severity vulnerabilities were disclosed for NextGen Mirth Connect and other systems. CVE-2026-82583 (High, CVSSv3 8.3) allows authenticated users to execute arbitrary SQL via the Database Connector API, potentially leading to credential theft and file writes. CVE-2026-78224 (High, CVSSv3 7.5) and CVE-2026-82578 (High, CVSSv3 7.5) are XXE injection flaws in Mirth Connect. CVE-2026-81640 (High, CVSSv3 8.8) allows an attacker to derive a camera's Wi-Fi password, potentially exposing live video streams and device services. CVE-2026-77974 (High, CVSSv3 8.0) enables an attacker to trigger firmware updates through an unauthenticated channel after spoofing the device. CVE-2026-81823 (Medium, CVSSv3 5.3) from AVEVA Pipeline Integrity Monitor allows unauthenticated information disclosure.

The disclosures were coordinated across multiple advisories, including CISA alerts for NextGen Healthcare Mirth Connect (CVE-2026-78224, CVE-2026-82578, CVE-2026-82583), Orthanc DICOM Server (CVE-2026-87020), and AVEVA Pipeline Integrity Monitor (CVE-2026-81823, CVE-2026-81824). These advisories provide critical details on affected versions and potential impacts, such as credential exfiltration and denial-of-service conditions.

Users of Cisagov Csaf, NextGen Healthcare Mirth Connect, Orthanc DICOM Server, and AVEVA Pipeline Integrity Monitor should urgently review the specific CVEs affecting their deployed versions. The wide range of vulnerabilities, from weak credential handling to complex injection flaws, necessitates a thorough security assessment and prompt application of available patches or mitigations. The coordinated disclosure across multiple vendors underscores the importance of staying informed about security advisories and maintaining up-to-date systems to protect against these diverse threats.

The vulnerabilities disclosed in this batch include:

This batch of vulnerabilities spans multiple products and diverse attack vectors, emphasizing the need for comprehensive security practices. Users are strongly advised to consult vendor advisories and apply necessary updates.

AI-written article. Grounded in 24 CVE records listed below.