Medical Device Cybersecurity Intelligence

Real-time alerts from FDA Safety Communications, CISA Known Exploited Vulnerabilities, and NIST NVD — filtered for life-critical medical devices. Data is polled every 30 minutes from all three sources. The dashboard auto-refreshes every 10 minutes. Life-critical device alerts are highlighted in red. GET ALERTED when new medical device cybersecurity alerts are published.

63 Critical
365 High
40 Medium
468 Total
Clear

Last updated: 2026-08-21 22:15 UTC

CRITICAL NVD CVSS 9.1

CVE-2026-55471 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or AC…

CRITICAL CISA-KEV

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

CRITICAL CISA-KEV

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

CRITICAL NVD CVSS 9.3

CVE-2026-34361 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined w…

CRITICAL CISA-KEV

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager (EPM)

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

CRITICAL CISA-KEV

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

HIGH ⚕ LIFE CRITICAL NVD CVSS 8.6

CVE-2026-10649 — Pacemaker Vulnerability

pacemaker

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, le…

HIGH ⚕ LIFE CRITICAL FDA

Merit Medical Systems, Inc. — CentrosFLO Hemodialysis Catheters, REF: CENFP15K/A, CENFP15K/B, CENFP17K/A, CENFP19K/A, CENFP23K/A,

Merit Medical Systems, Inc. CentrosFLO Hemodialysis Catheters, REF: CENFP15K/A, CENFP15K/B, CENFP17K/A, CENFP19K/A, CENFP23K/A, CENFP27K/A, CENFP31K/A, CENFT15K, CENFT15K/D, CENFT17K, CENFT17K/A, CENFT17K/D, CENFT19K, CENFT19K/A

16F dual-valved splittable sheath introducer due to a design defect, may not split as intended, which may result in hemorrhage, foreign bodies, procedure delay, embolization/thrombosis, impaired catheter function, loss of vessel for future vascular access.

HIGH ⚕ LIFE CRITICAL FDA

Merit Medical Systems, Inc. — ProGuide Chronic Dialysis Catheters, REF: DC01455550/C, DC21452419/C, DC21452419-NE5/C, DC21452823-N

Merit Medical Systems, Inc. ProGuide Chronic Dialysis Catheters, REF: DC01455550/C, DC21452419/C, DC21452419-NE5/C, DC21452823-NE5/C, DC21454035/C, DC21455550/C

16F dual-valved splittable sheath introducer due to a design defect, may not split as intended, which may result in hemorrhage, foreign bodies, procedure delay, embolization/thrombosis, impaired catheter function, loss of vessel for future vascular access.

HIGH ⚕ LIFE CRITICAL FDA

Merit Medical Systems, Inc. — DuraMax Chronic Hemodialysis Catheter, REF: H787103028015/A, H787103028025/A, H787103028031/A, H7871

Merit Medical Systems, Inc. DuraMax Chronic Hemodialysis Catheter, REF: H787103028015/A, H787103028025/A, H787103028031/A, H787103028035/A, H787103028041/A, H787103028045/A, H787103028051/A, H787103028055/A, H787103028061/A, H78

16F dual-valved splittable sheath introducer due to a design defect, may not split as intended, which may result in hemorrhage, foreign bodies, procedure delay, embolization/thrombosis, impaired catheter function, loss of vessel for future vascular access.

HIGH NVD CVSS 7.5

CVE-2026-62295 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but dee…

HIGH NVD CVSS 7.5

CVE-2026-62296 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and …

HIGH FDA

Bard Access Systems, Inc. — BD Needle Kit for Powered Driver 15mm x 15Ga, REF: D015151NK, BD Needle Kit for Powered Driver 25mm

Bard Access Systems, Inc. BD Needle Kit for Powered Driver 15mm x 15Ga, REF: D015151NK, BD Needle Kit for Powered Driver 25mm x 15Ga, REF: D015251NK, BD Needle Kit for Powered Driver 35mm x 15Ga, REF: D015351NK, BD Needle K

After placement of intraosseous (IO) needle sets, used when intravenous access is difficult or impossible to obtain in emergent, urgent, or medically necessary cases, users may experience difficulty/inability to remove obturator, due to it locking to the needle hub, due to out-of…

HIGH FDA

Bard Access Systems, Inc. — BD Needle Kit for Powered Driver 15mm x 15Ga, REF: D015151NK, BD Needle Kit for Powered Driver 25mm

Bard Access Systems, Inc. BD Needle Kit for Powered Driver 15mm x 15Ga, REF: D015151NK, BD Needle Kit for Powered Driver 25mm x 15Ga, REF: D015251NK, BD Needle Kit for Powered Driver 35mm x 15Ga, REF: D015351NK, BD Needle Kit

After placement of intraosseous (IO) needle sets, used when intravenous access is difficult or impossible to obtain in emergent, urgent, or medically necessary cases, users may experience difficulty/inability to remove obturator, due to it locking to the needle hub, due to out-of…

HIGH NVD CVSS 7.5

CVE-2026-49485 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation, and the FHIRPath functions …

HIGH NVD CVSS 7.5

CVE-2026-45367 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations witho…

HIGH NVD CVSS 7.5

CVE-2026-55470 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw…

HIGH FDA

Galt Medical Corporation — Boston Scientific Enhance Transcarotid/Peripheral Access Kit REF: SR-4F21G7D-MP (Kit-075-03) Sheat

Galt Medical Corporation Boston Scientific Enhance Transcarotid/Peripheral Access Kit REF: SR-4F21G7D-MP (Kit-075-03) Sheath with Dilator , Stiffen Dilator, Nitinol Mandrel Wire w/ Radiopaque Tip [Au}, Needle, Extension Tub

Black depth markings may detach from the outer sheath of the coaxial dilator introducer component of transcarotid-peripheral access kits.

HIGH FDA

Galt Medical Corporation — Boston Scientific Enhance Transcarotid/Peripheral Access Kit REF: SR-4F21G7D-MP (Kit-075-03) Sheath

Galt Medical Corporation Boston Scientific Enhance Transcarotid/Peripheral Access Kit REF: SR-4F21G7D-MP (Kit-075-03) Sheath with Dilator , Stiffen Dilator, Nitinol Mandrel Wire w/ Radiopaque Tip [Au}, Needle, Extension Tube

Black depth markings may detach from the outer sheath of the coaxial dilator introducer component of transcarotid-peripheral access kits.

HIGH FDA

Medtronic Neurosurgery — Ventriculostomy Kit, REF: 46154

Medtronic Neurosurgery Ventriculostomy Kit, REF: 46154

Ventriculostomy devices, used during ventriculostomy procedures to gain access to the ventricular system, may exhibit endotoxin levels that exceed the acceptable limit for devices that come into contact with cerebrospinal fluid; endotoxin exposure can cause an acute inflammatory …

HIGH FDA

PHILIPS MEDICAL SYSTEMS NEDERLAND B.V. — Philips Allura under the following System Descriptions and corresponding model numbers: 1. Allura

PHILIPS MEDICAL SYSTEMS NEDERLAND B.V. Philips Allura under the following System Descriptions and corresponding model numbers: 1. Allura Xper FD10; Model Numbers: 722003, 722010, 722026. 2. Allura Xper FD10 OR Table; Model Number: 7220

Potential Loss of imaging functionality, loss of motorized movement, or loss of data due to unauthorized Hard Disk Drives.

HIGH FDA

PHILIPS MEDICAL SYSTEMS NEDERLAND B.V. — Philips Azurion under the following System Descriptions and corresponding model numbers: 1. Azurio

PHILIPS MEDICAL SYSTEMS NEDERLAND B.V. Philips Azurion under the following System Descriptions and corresponding model numbers: 1. Azurion 3 M12; Model Numbers: 722063, 722221. 2. Azurion 3 M15; Model Numbers: 722064, 722222, 722280.

Potential Loss of imaging functionality, loss of motorized movement, or loss of data due to unauthorized Hard Disk Drives.

HIGH FDA

Argon Medical Devices, Inc — L-Cath PICC S/L Peripherally Inserted Central Catheter: 26ga (1.9F) 0.60mm x 30cm, REF: 384539; 18ga

Argon Medical Devices, Inc L-Cath PICC S/L Peripherally Inserted Central Catheter: 26ga (1.9F) 0.60mm x 30cm, REF: 384539; 18ga (3.5F) 1.15mm x 60cm, REF: 384464; Basic Kit 28GA (1.2F) x 25cm 1 Lumen), REF: 384516; 20ga (3F) 1.

Catheters, indicated for short/long-term peripheral access to central venous system for the administration of fluids, medications, nutrients; and sampling, may experience leaking and/or cracking at the hub, which may lead to replacement, inability to flush/aspirate catheter, cath…

HIGH FDA

Argon Medical Devices, Inc — L-Cath Midline S/L Catheter 20ga (3F) 1mm x 20cm, REF: 384620

Argon Medical Devices, Inc L-Cath Midline S/L Catheter 20ga (3F) 1mm x 20cm, REF: 384620

Catheters, indicated for short/long-term peripheral access to central venous system for the administration of fluids, medications, nutrients; and sampling, may experience leaking and/or cracking at the hub, which may lead to replacement, inability to flush/aspirate catheter, cath…

HIGH FDA

CMR SURGICAL LIMITED 1 Evolution Business Park Milton Road; Cam Cambridge United Kingdom — Brand Name: Versius Surgical System US Product Name: Vesius Surgeon Console US Model/Catalog Numbe

CMR SURGICAL LIMITED 1 Evolution Business Park Milton Road; Cam Cambridge United Kingdom Brand Name: Versius Surgical System US Product Name: Vesius Surgeon Console US Model/Catalog Number: V-SS-1020 Software Version: Pratchett 1 version 62.1 Product Description: The Versius Surgical

Secure Boot was mistakenly not enabled at manufacturing time, which presents a potential cybersecurity risk.

HIGH FDA

CMR SURGICAL LIMITED 1 Evolution Business Park Milton Road; Cam Cambridge United Kingdom — Brand Name: Versius Surgical System US Product Name: Vesius Surgeon Console US Model/Catalog Number:

CMR SURGICAL LIMITED 1 Evolution Business Park Milton Road; Cam Cambridge United Kingdom Brand Name: Versius Surgical System US Product Name: Vesius Surgeon Console US Model/Catalog Number: V-SS-1020 Software Version: Pratchett 1 version 62.1 Product Description: The Versius Surgical Syst

Secure Boot was mistakenly not enabled at manufacturing time, which presents a potential cybersecurity risk.

HIGH FDA

PIE Medical Imaging B.V. Demertdwarsstraat 8A01 Maastricht Netherlands — 3mensio Workstation (Vascular Fenestrated) software

PIE Medical Imaging B.V. Demertdwarsstraat 8A01 Maastricht Netherlands 3mensio Workstation (Vascular Fenestrated) software

User measurement value reported by diagnostic bioimaging software intended to measure/visualize cardiovascular structures may be larger (0.8% to 34.4%) than the actual anatomical dimension, if all the following occur: affected software is used, and the user has access only to 3D …

HIGH FDA

— SD LTM 64 PLUS, EEG Amplifier/recorder, Model/Catalog Number: SD LTM 64 PLUS, Software Version: firm

SD LTM 64 PLUS, EEG Amplifier/recorder, Model/Catalog Number: SD LTM 64 PLUS, Software Version: firmware 2021.02, 2022.01 or 2022.02

Natus has become aware of two complaints related to the SD LTM 64 PLUS where the EEG traces acquired from two or four different amplifiers used in a multiple amplifier configuration (128 or 256 channels) running firmware version 2022.02 were displayed with a shift of 1 second bet…

HIGH FDA

Micromed S.p.A. — SD LTM 64 PLUS, EEG Amplifier/recorder, Model/Catalog Number: SD LTM 64 PLUS, Software Version: firm

Micromed S.p.A. SD LTM 64 PLUS, EEG Amplifier/recorder, Model/Catalog Number: SD LTM 64 PLUS, Software Version: firmware 2021.02, 2022.01 or 2022.02

Natus has become aware of two complaints related to the SD LTM 64 PLUS where the EEG traces acquired from two or four different amplifiers used in a multiple amplifier configuration (128 or 256 channels) running firmware version 2022.02 were displayed with a shift of 1 second bet…

HIGH FDA

Fresh Roast Systems Inc — Fresh Roast Systems ColorTrack. Model Name: ColorTrack. Model Number: BENCH R-100

Fresh Roast Systems Inc Fresh Roast Systems ColorTrack. Model Name: ColorTrack. Model Number: BENCH R-100

A defect has been identified in the manufacture of the Fresh Roast Systems ColorTrack instrument model number BENCH R-100 which could under very rare specific misuse circumstances potentially allow human access to infrared laser light levels in excess of the safety Classification…

HIGH FDA

Fresh Roast Systems Inc — Fresh Roast Systems ColorTrack. Model Name: ColorTrack. Model Number: BENCH R-100

Fresh Roast Systems Inc Fresh Roast Systems ColorTrack. Model Name: ColorTrack. Model Number: BENCH R-100

A defect has been identified in the manufacture of the Fresh Roast Systems ColorTrack instrument model number BENCH R-100 which could under very rare specific misuse circumstances potentially allow human access to infrared laser light levels in excess of the safety Classification…

HIGH NVD CVSS 7.4

CVE-2026-34359 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch.…

HIGH FDA

GE Medical Systems, LLC — Revolution Ascend, computed tomography, Model Numbers 6969000-100 and 6969000-300

GE Medical Systems, LLC Revolution Ascend, computed tomography, Model Numbers 6969000-100 and 6969000-300

GE HealthCare has become aware of a potential security vulnerability impacting AW Server deployed via Edison Health Link (EHL) based CT Smart Subscription used in conjunction with certain Revolution Apex, Revolution Ascend, and Revolution CT systems.

HIGH NVD CVSS 7.5

CVE-2026-33180 — Hl7 Fhir Vulnerability

HL7 FHIR

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirec…

HIGH FDA

Beckman Coulter, Inc. — Access Total T4 Calibrator, Catalog No. 33805

Beckman Coulter, Inc. Access Total T4 Calibrator, Catalog No. 33805

Beckman Coulter has identified that Access Total T4 Calibrator lots (PN 33805) exhibit a negative bias on DxI 600/800 instruments, with slopes outside product specifications. A false low patient result could cause a patient to undergo unnecessary additional diagnostic testing. A …

HIGH NVD CVSS 8.1

CVE-2025-67752 — Electronic Health Record Vulnerability

electronic health record

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HT…

HIGH NVD CVSS 8.7

CVE-2025-69231 — Electronic Health Record Vulnerability

electronic health record

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject malicio…

HIGH FDA

Merit Medical Systems, Inc. — 16F Dual Valved Splittable Sheath Introducer (bulk, non-sterile), REF: FCL-174-00/B

Merit Medical Systems, Inc. 16F Dual Valved Splittable Sheath Introducer (bulk, non-sterile), REF: FCL-174-00/B

16F dual-valved splittable sheath introducer due to a design defect, may not split as intended, which may result in hemorrhage, foreign bodies, procedure delay, embolization/thrombosis, impaired catheter function, loss of vessel for future vascular access.

HIGH FDA

Merit Medical Systems, Inc. — BioFlo DuraMax Catheter, REF: H965103028011/A, H965103028021/A, H965103028021/EU, H965103028031/A, H

Merit Medical Systems, Inc. BioFlo DuraMax Catheter, REF: H965103028011/A, H965103028021/A, H965103028021/EU, H965103028031/A, H965103028031/EU, H965103028041/A, H965103028041/EU, H965103028051/A, H965103028051/EU, H965103028061

16F dual-valved splittable sheath introducer due to a design defect, may not split as intended, which may result in hemorrhage, foreign bodies, procedure delay, embolization/thrombosis, impaired catheter function, loss of vessel for future vascular access.

HIGH FDA

GE Medical Systems, LLC — Centricity Universal Viewer Software Versions 7.0 through 7.0 Sp2.0.1, a device that displays medica

GE Medical Systems, LLC Centricity Universal Viewer Software Versions 7.0 through 7.0 Sp2.0.1, a device that displays medical images (including mammograms) and data from various imaging sources, Model Numbers 5826659-027, 58

There is a potential cybersecurity vulnerability affecting certain versions of Centricity Universal Viewer. User login credentials may be exposed on the local client workstation, which could allow an unauthorized individual to potentially impact system availability and/or manipul…

HIGH FDA

GE Medical Systems, LLC — Centricity Universal Viewer Software Versions 6.0 through 6.0 Sp10.4.1, a device that displays medic

GE Medical Systems, LLC Centricity Universal Viewer Software Versions 6.0 through 6.0 Sp10.4.1, a device that displays medical images (including mammograms) and data from various imaging sources, Model Numbers 2088026-406, 2

There is a potential cybersecurity vulnerability affecting certain versions of Centricity Universal Viewer. User login credentials may be exposed on the local client workstation, which could allow an unauthorized individual to potentially impact system availability and/or manipul…

HIGH FDA

GE Medical Systems, LLC — Centricity Universal Viewer Software Versions 5.0 SP6 through UV 5.0 SP7.1, a device that displays m

GE Medical Systems, LLC Centricity Universal Viewer Software Versions 5.0 SP6 through UV 5.0 SP7.1, a device that displays medical images (including mammograms) and data from various imaging sources, Model Numbers 2088026-02

There is a potential cybersecurity vulnerability affecting certain versions of Centricity Universal Viewer. User login credentials may be exposed on the local client workstation, which could allow an unauthorized individual to potentially impact system availability and/or manipul…

HIGH NVD CVSS 8.8

CVE-2025-67645 — Electronic Health Record Vulnerability

electronic health record

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference a…

HIGH FDA

Auris Health, Inc — MONARCH Platform, Bronchoscopy, Catalog Numbers: MON-000005-01 , MON-000005-01R , MON-000006 , MON-0

Auris Health, Inc MONARCH Platform, Bronchoscopy, Catalog Numbers: MON-000005-01 , MON-000005-01R , MON-000006 , MON-000006-RFB, MON-000008 with software

Device for bronchoscopic visualization, patient airway access has software issue: if application restarts after patient-side selection, prior to bronchoscope loading, application will re-initialize to patient-left position; and if right position was previously selected, this may …

MEDIUM ⚕ LIFE CRITICAL NVD CVSS 6.5

CVE-2026-19391 — Pacemaker Vulnerability

pacemaker

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in arc…

MEDIUM NVD CVSS 6.1

CVE-2026-21443 — Electronic Health Record Vulnerability

electronic health record

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()` …

MEDIUM NVD CVSS 6.5

CVE-2025-54373 — Electronic Health Record Vulnerability

electronic health record

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encou…

Get Alerted

Receive email notifications when new medical device cybersecurity alerts are published.