BridgeLink, the open source fork of NextGen Healthcare's Mirth Connect, shipped version 26.9.0 on October 1. The release closes the three high severity flaws CISA listed in advisory ICSMA-26-253-01 on September 10: a SQL injection in the Database Connector API, CVE-2026-82583, CVSS v4 7.2, and two XML external entity flaws, CVE-2026-78224 at 8.8 and CVE-2026-82578 at 8.7. All three hit Mirth Connect 4.7.1 and earlier. NextGen's own commercial fix landed as version 4.7.2 the week the advisory published. BridgeLink users waited three more weeks for the same coverage.
SQL injection in the Database Connector API means a crafted HL7 or FHIR message reaching the backend as part of a live query, no credentials required beyond whatever channel already accepts inbound feeds. The two XXE flaws work differently: a malformed XML payload hits the XSLT transformer step or the XPath and JAXP configuration, and the parser resolves external entities it should refuse. That leaks data or crashes the channel outright.
An integration engine like Mirth Connect or BridgeLink sits at the center of hospital data plumbing, routing lab results, device telemetry, and orders between systems that were never built to talk to each other directly. A compromised instance can expose far more than one device, reaching everything flowing through it: infusion pump logs, imaging orders, monitor alarms, whatever HL7 feed happens to be configured that week.
The release also retired a backlog of inherited third party CVEs instead of patching around them. XStream moved to 1.4.21, closing CVE-2024-47072. BouncyCastle jumped to 1.86, closing CVE-2025-14813 along with CVE-2026-0636, CVE-2025-8916, CVE-2026-5588, CVE-2026-8763, and CVE-2026-13506. The Rhino JavaScript engine lost its CPU exhaustion denial of service path, CVE-2025-66453. Apache Derby's LDAP authentication bypass, CVE-2022-46337, is gone. Jackson picked up fixes for CVE-2025-52999 and CVE-2026-19032, and the PostgreSQL and Microsoft SQL Server JDBC drivers moved to versions closing CVE-2026-54291 and CVE-2025-59250.
Innovar Healthcare, which maintains BridgeLink, called it a security focused release built around eliminating unmaintained libraries rather than patching around them indefinitely, the harder but more durable fix. It is also the real cost of a fork: when an upstream project changes its distribution model, as NextGen did when it moved Mirth Connect's free edition behind a commercial license, the fork's maintainers become the only patch source left for every install that stayed open source.
Three weeks separated the two fixes, which is fast for a release spanning eight distinct libraries and nine CVEs across a four year span of disclosure dates. Hospitals running the open source lineage had no commercial support contract to escalate through while they waited, and most integration engines are the kind of infrastructure nobody inventories until something breaks.
An integration engine is not a device, but every device's data runs through it. Inventory it the same way.