NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates