Statistics · Medical device cybersecurity
Medical Device Vulnerabilities: 536 CVEs, 12 on CISA's Exploited List
CISA's medical advisories directly name 536 distinct medical device vulnerabilities in 192 notices since 2016. Twelve (2.2%) are on CISA's exploited list, all Microsoft or Apache flaws, according to The PenTest Index's October 2026 analysis of CISA advisories. The often-quoted "6.2 per device" figure appears in a 2018 vendor blog post.
CISA is the U.S. cyber defense agency. A vulnerability is a security flaw. A CVE is a public ID for a disclosed flaw. Our exploited count means the flaw is on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Being off that list does not prove a flaw has never been used.
This page counts CVE IDs printed on CISA's advisory pages. One linked maker table adds 162 more IDs. It is not a safety rating for any device.
Key medical device vulnerability statistics
- 536 vulnerabilities, 192 advisories. CISA published 192 medical device security advisories from March 29, 2016 to October 8, 2026. They directly name 536 different vulnerabilities (CVEs). (The PenTest Index analysis of CISA ICS medical advisories.)
- 12 of 536 (2.2%) are on CISA's exploited list. Twelve are on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Eleven are Microsoft flaws and one is an Apache Tomcat flaw. None of these 12 catalog matches is a flaw in a device maker's own code. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- 0 of 77. No CISA medical advisory with a 2022 to 2026 number lists a CVE on CISA's exploited list as of October 8, 2026. The 12 sit in six advisories from 2017 to 2021. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- 49.4% are high or critical. Of the 512 vulnerabilities with a single CVSS v3 score, 253 are rated high or critical, and 93 (18.2%) are critical. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- 39.2% are access control flaws. 210 of the 536 fall in MITRE's access control group. 152 (28.4%) are authentication flaws: weak checks of a claimed identity. 42 (7.8%) are hard-coded or default passwords and keys. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- 76.8% need no prior privileges. 393 of the 512 scored vulnerabilities do not require the attacker to hold access rights before the attack. 257 (50.2%) can be reached over a network. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- Four makers, 45.8% of advisories. Philips (41), BD (23), Medtronic (15) and Baxter (9) are named in 88 of 192 advisories. In 2025 and 2026 they are named in 2 of 39. (The PenTest Index analysis of CISA medical advisories through October 8, 2026.)
- Imaging software: 10.0% to 48.4%. Imaging software was the subject of 13 of 130 advisories in 2016 to 2022 and 30 of 62 in 2023 to 2026. (The PenTest Index analysis of CISA medical advisories through October 8, 2026; device groups are our own sorting.)
- Two older reports list 1,418 and 460 flaws. Two 2016 CISA advisories report these counts for outside software in two products without listing each CVE. Their sum is 1,878, but overlap is unknown, so it is not a count of 1,878 different flaws. (CISA advisories ICSMA-16-089-01 and ICSMA-16-196-01; sum by The PenTest Index.)
- 11 of FDA's 18. Eleven of the 18 notices in the FDA's cybersecurity safety communications table (June 2013 to January 2025) match a CISA medical advisory in this dataset. (The PenTest Index matching, checked October 9, 2026 (UTC).)
- 74.5% credit an outside or anonymous reporter. 143 of 192 advisories credit an outside or anonymous reporter with finding or reporting the flaw. 49 credit only the maker. (The PenTest Index reading of CISA medical advisories through October 8, 2026.)
- The original "6.2 vulnerabilities per medical device" post gives no method. The earliest source we found is a February 7, 2018 Sensato blog post that gives no sample, dates or method. The FBI repeated the figure in 2022 and the GAO repeated the FBI in 2023.
Source for our counts: The PenTest Index analysis of CISA ICS medical advisories and the CISA Known Exploited Vulnerabilities catalog (version 2026.10.08). Data as of October 8, 2026.
The count at a glance
| Measure | Count | Share |
|---|---|---|
| CISA medical advisories, March 29, 2016 to October 8, 2026 | 192 | |
| Different vulnerabilities (CVEs) named | 536 | 100% |
| Rated high or critical (of 512 with a single score) | 253 | 49.4% |
| On CISA's Known Exploited Vulnerabilities list | 12 | 2.2% |
| Device-maker-code flaws among the 12 catalog matches | 0 | 0% of the 12 |
Source: The PenTest Index analysis of CISA ICS medical advisories and the CISA Known Exploited Vulnerabilities catalog, October 8, 2026.
How many medical device vulnerabilities are there?
CISA's medical advisory pages directly name 536 medical device vulnerabilities in 192 advisories, from March 29, 2016 to October 8, 2026. That is about 18 advisories a year. The count covers flaws CISA has published, not every flaw that exists.
Think of an advisory as a security warning for software. One notice can cover one flaw or many. The biggest one here lists 35. Of the 188 notices that name CVEs, almost half (88) list just one.
How many advisories does CISA publish each year?
The busiest year was 2018, with 32 advisories. The quietest full year was 2023, with 10. In 2025 the count jumped back to 24, and 15 of those were about imaging software.
CISA medical advisories by year, 2016 to October 8, 2026
| Year | Advisories | CVE listings | About imaging software | Naming Philips, BD, Medtronic or Baxter |
|---|---|---|---|---|
| 2016 | 4 | 5 | 0 | 2 |
| 2017 | 16 | 33 | 2 | 6 |
| 2018 | 32 | 123 | 7 | 21 |
| 2019 | 20 | 49 | 1 | 14 |
| 2020 | 24 | 88 | 1 | 14 |
| 2021 | 19 | 88 | 1 | 8 |
| 2022 | 15 | 26 | 1 | 10 |
| 2023 | 10 | 26 | 3 | 5 |
| 2024 | 13 | 27 | 6 | 6 |
| 2025 | 24 | 57 | 15 | 2 |
| 2026 (to Oct 8) | 15 | 29 | 6 | 0 |
| Total | 192 | 551 | 43 | 88 |
Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Year is the year in CISA's advisory number. Fifteen CVEs appear in two advisories, so the yearly listings add to 551, not 536. Device groups are our own sorting.
What counts as one vulnerability?
One CVE counts as one vulnerability, no matter how many advisories repeat it. That is why the total is 536 and not 551.
- Advisory: one notice from CISA. CISA calls these ICS medical advisories. Each has a number like ICSMA-25-030-01: the year, the day of the year, and a counter.
- CVE: the public ID for one flaw.
- Four advisories list no CVE numbers at all. They describe groups of flaws instead. They are counted in the 192.
- The series starts in 2016. A few older medical notices carried a different kind of number and are not here.
How many medical device vulnerabilities are used in real attacks?
Twelve in this dataset are on CISA's exploited list. Of the 536 vulnerabilities, 12 (2.2%) are on CISA's Known Exploited Vulnerabilities list as of October 8, 2026. Eleven are Microsoft flaws and one is an Apache Tomcat flaw. None of these 12 catalog matches is a flaw in a device maker's own code.
CISA keeps a list of flaws that attackers have really used. A flaw gets on it only when three things are true: it has a CVE number, there is reliable evidence it has been actively exploited, and there is a clear action to address the flaw. CISA includes attempted as well as successful exploitation. Scanning, research and proof-of-concept code do not count.
Which 12 are known exploited?
All 12 are old flaws in common software: ten in Windows, one in Microsoft Office and one in Apache Tomcat. They show up in six advisories for imaging systems, a patient monitoring receiver and a drug-mixing system.
The 12 known exploited vulnerabilities named in CISA medical advisories
| CVE | Name on CISA's list | Where it turns up | Advisory | Added to the list | Ransomware use (per CISA) |
|---|---|---|---|---|---|
| CVE-2008-4250 | Microsoft Windows Buffer Overflow | Siemens molecular imaging systems on Windows XP | ICSMA-17-215-01 | May 20, 2026 | Unknown |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution | Siemens molecular imaging systems on Windows 7 | ICSMA-17-215-02 | Feb 10, 2022 | Unknown |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution | Philips IntelliSpace Portal; Baxter ExactaMix | ICSMA-18-058-02; ICSMA-20-170-01 | Nov 3, 2021 | Known |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution | Philips IntelliSpace Portal | ICSMA-18-058-02 | Feb 10, 2022 | Known |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution | Philips IntelliSpace Portal | ICSMA-18-058-02 | Feb 10, 2022 | Known |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution | Philips IntelliSpace Portal | ICSMA-18-058-02 | Mar 25, 2022 | Known |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure | Philips IntelliSpace Portal | ICSMA-18-058-02 | May 24, 2022 | Known |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution | Philips IntelliSpace Portal | ICSMA-18-058-02 | Apr 6, 2022 | Known |
| CVE-2017-0199 | Microsoft Office and WordPad Remote Code Execution | Philips IntelliSpace Portal | ICSMA-18-058-02 | Nov 3, 2021 | Known |
| CVE-2017-7269 | Microsoft Windows Server Buffer Overflow | Siemens molecular imaging systems on Windows XP | ICSMA-17-215-01 | Nov 3, 2021 | Unknown |
| CVE-2019-0708 | Microsoft Remote Desktop Services Remote Code Execution | Spacelabs Xhibit Telemetry Receiver | ICSMA-20-049-01 | Nov 3, 2021 | Known |
| CVE-2020-1938 | Apache Tomcat Improper Privilege Management | Philips Vue PACS | ICSMA-21-187-01 | Mar 3, 2022 | Unknown |
Source: The PenTest Index match of CISA ICS medical advisories against the CISA Known Exploited Vulnerabilities catalog, version 2026.10.08 (1,739 entries), October 8, 2026.
Three things stand out.
- The 12 sit in six advisories, all from 2017 to 2021.
- No advisory numbered 2022 or later lists one (0 of 77).
- The oldest carries a 2008 CVE number. CISA added it to its list on May 20, 2026.
One more flaw sits just outside this count. CVE-2023-43208, in NextGen Healthcare's Mirth Connect, has been on CISA's exploited list since May 20, 2024. No CISA medical advisory names it, so it is not one of the 536. CISA's September 2026 advisory for Mirth Connect (ICSMA-26-253-01) lists three other flaws.
Why are all 12 in borrowed software?
Many medical devices use common computer software. A device can inherit a flaw in the software it uses. All 12 catalog matches here are in that outside software.
- CISA's Siemens advisory says the flaws are in imaging products "running on Windows XP".
- CISA's Spacelabs advisory names the flaw BlueKeep and says an exploit "would be capable of rapidly spreading like the WannaCry malware attacks of 2017".
- One 2016 advisory says a hospital supply cabinet (the CareFusion Pyxis SupplyStation) had 1,418 known flaws in 7 outside software packages. Another says a Philips system had 460: 272 in five software packages and 188 in Windows XP.
- Add those reported counts: 1,418 + 460 = 1,878. The two lists may overlap with each other and with the 536 named CVEs, so we cannot call these 1,878 extra, different flaws. CISA's two pages put 715 and 360 at a score of 7.0 or higher: a reported sum of 1,075. These 2016 totals are kept apart from our CVSS v3 analysis.
Picture a house where the builder bought the front door lock from someone else. If that lock has a known trick, every house with that lock has the trick.
What does 12 of 536 not prove?
Twelve is the number of matches to CISA's catalog. It is not proof that the other 524 have never been used. CISA adds a flaw only with reliable evidence and a clear action to address it, so a quiet attack on one device may never make the list.
- It does not mean devices are safe. Companies that scan hospital networks find known exploited flaws on real devices. Claroty reported in March 2025 that 9% of the connected medical devices it analyzed carried a known exploited flaw, across 99% of the 351 organizations in its sample.
- Both numbers can be true. Ours counts flaws CISA named. Claroty's counts devices on hospital networks. In our data, the catalog matches are old Windows, Office and Tomcat flaws in device software.
- One advisory hides a longer list. The Biosense Webster Carto 3 advisory (ICSMA-18-107-02) prints no CVE numbers. It points to a Johnson & Johnson table instead. We checked the original Johnson & Johnson PDF. It has 183 different CVE IDs, 21 already in our data and 162 more. Add those IDs and the set is 698, with 20 (2.9%) on CISA's exploited list: 19 Microsoft and one Apache. The pattern holds. The 183-row source file gives each PDF page and the match. Rows with only Microsoft bulletin or update numbers are not turned into extra CVEs.
Has a hacked medical device hurt a patient?
The FDA says it is not aware of one in the cases it lists. Its cybersecurity page lists 18 safety notices from June 2013 to January 2025 and says: "In each of the following cases, the FDA is not aware of any patient injuries or deaths associated with cybersecurity incidents."
That sentence covers those 18 cases. It is not a promise about every device.
- The GAO, a federal watchdog, wrote in December 2023: "Although cyber incidents impacting medical devices have occurred, they are not common."
- The FDA's 2026 guidance also warns: "Cyber incidents have rendered medical devices and hospital networks inoperable, disrupting the delivery of patient care."
- The FDA's recall database lists 17 recall events that give "cybersecurity" in the reason, started between February 2019 and September 2026. This keyword search is not a full count of cybersecurity recalls or attacks. It returns 60 product records; we counted the 17 different recall event numbers.
- Two other recall records name malware: a 2008 recall of an ultrasound imaging system warned of possible computer-worm infection; a 2021 recall of cloud-hosted cancer-care software gives its reason as "Malware attack".
How serious are medical device vulnerabilities?
About half are serious on paper. Of the 512 vulnerabilities with a single score, 253 (49.4%) are rated high or critical, and 93 (18.2%) are critical, the top band.
CVSS, the Common Vulnerability Scoring System, rates a flaw from 0 to 10. Not every flaw has a published score. Think of it like a storm rating. It tells you how strong the storm could be. It does not tell you whether it will hit your house.
Medical device vulnerabilities by severity (CVSS v3)
| Band | CVSS score | Vulnerabilities | Share of 512 |
|---|---|---|---|
| Critical | 9.0 to 10.0 | 93 | 18.2% |
| High | 7.0 to 8.9 | 160 | 31.3% |
| Medium | 4.0 to 6.9 | 230 | 44.9% |
| Low | 0.1 to 3.9 | 29 | 5.7% |
| High or critical | 7.0 to 10.0 | 253 | 49.4% |
| All with a single score | 512 | 100% |
Source: The PenTest Index analysis of scores printed in CISA ICS medical advisories, October 8, 2026. Bands follow FIRST's CVSS v3.1 scale. Twenty-four vulnerabilities in one 2018 advisory have only a score range and are left out. Shares are rounded one at a time, so 18.2% and 31.3% look like 49.5%, but 253 of 512 is 49.4%.
Here is the odd part. Of the 93 critical flaws, 88 (94.6%) are not on the known exploited list. A scary score and a real attack are two different things.
How would an attacker reach a medical device?
Half have a network attack path. Of the 512 scored vulnerabilities, 257 (50.2%) can be reached over a network, and 393 (76.8%) need no prior privileges: access rights held before the attack.
Where the attacker has to be
| Where the attacker has to be | What it means | Vulnerabilities | Share of 512 |
|---|---|---|---|
| Network | Anywhere that can reach the device over a network. Like calling a phone number. | 257 | 50.2% |
| Adjacent | On the same local or restricted network, or in radio range. Restricted-network access can be remote. | 112 | 21.9% |
| Local | Already on the device, or tricking a user into opening something. | 78 | 15.2% |
| Physical | Hands on the device. | 65 | 12.7% |
Source: as stated in the linked source line or in each row.
What the attack requires
| Fact | Vulnerabilities | Share of 512 |
|---|---|---|
| No prior privileges needed | 393 | 76.8% |
| No action by a user needed | 427 | 83.4% |
| Rated low complexity (no special conditions beyond the attacker's control) | 394 | 77.0% |
| All four at once: network, low complexity, no prior privileges, no user action | 149 | 29.1% |
Source: as stated in the linked source line or in each row.
Source for both tables: The PenTest Index analysis of CVSS v3 vectors printed in CISA ICS medical advisories, October 8, 2026. A vector records the conditions used to score a flaw. The FIRST definitions do not say every network-rated device is exposed to the public internet, or that a low-complexity attack is easy for anyone to carry out.
What do the scores leave out?
A score rates the software flaw. It does not rate what could happen to a patient. A flaw in a picture viewer and a flaw in an insulin pump can get the same number.
FIRST, the group that runs CVSS, says the base score measures severity, not risk.
What are the most common medical device vulnerabilities?
Access control flaws. Of the 536 vulnerabilities, 210 (39.2%) are access control flaws, which means the product does not check well enough who you are or what you are allowed to do. That is about 4.5 times the next kind.
The seven most common kinds of medical device vulnerability
| Kind (MITRE group) | In plain words | Vulnerabilities | Share of 536 | A real example |
|---|---|---|---|---|
| Access control | The product does not check well enough who you are or what you may do. | 210 | 39.2% | GE medical imaging products that used default or hard-coded credentials (ICSMA-18-037-02) |
| Encryption | Data is sent or stored without being scrambled, or the scrambling is weak. | 47 | 8.8% | Medtronic heart-device radio link that sent data in the clear (ICSMA-19-080-01) |
| Memory safety | The program reads or writes outside the memory it was given. | 47 | 8.8% | Natus brain-wave (EEG) software, scored 10.0 (ICSMA-18-165-01) |
| Injection | The product runs commands hidden in data someone sends it. | 35 | 6.5% | Baxter Connex Health Portal, scored 10.0 (ICSMA-24-249-01) |
| Sensitive information exposure | The product shows private data to someone who should not see it. | 29 | 5.4% | Dario Health blood glucose monitoring system (ICSMA-25-058-01) |
| Improper input validation | The product trusts what it is sent without checking it. | 28 | 5.2% | Spacelabs telemetry receiver (ICSMA-20-049-01) |
| Resource lifecycle management | The product mishandles files or resources. For example, it lets anyone upload any file. | 21 | 3.9% | BD Alaris Gateway Workstation, scored 10.0 (ICSMA-19-164-01) |
Source: The PenTest Index analysis. Weakness labels (CWEs) are the ones CISA printed. Groups are MITRE's CWE view 1400, not ours. Thirteen smaller groups hold 102 more vulnerabilities, and 17 use CWE category IDs that we keep ungrouped. Checked October 9, 2026 (UTC).
How many are authentication and password flaws?
More than one in four. Of the 536 vulnerabilities, 152 (28.4%) are authentication flaws: the product does not check a claimed identity well enough. That includes logins, certificates and device identities. Forty-two (7.8%) are hard-coded or default passwords and keys.
The three sets nest like boxes: 210 access control flaws, 152 authentication flaws inside those, and 42 built-in passwords or keys inside those.
A built-in password is like a spare key that is the same for every house the builder ever made. Find it once and you can open them all.
- The 42 sit in 37 advisories.
- One GE advisory adds 23 more. CISA describes them as "default or hard-coded credentials" but files them under a broader label. With those it is 65 (12.1%).
- Of the 93 critical flaws, 43 (46.2%) are authentication flaws.
- The FDA's guidance asks makers to test for credentials that are "'hardcoded,' default, easily guessed, and easily compromised."
Which weakness labels does CISA use most?
Improper Authentication (CWE-287) is the most used single label, on 45 of the 536 vulnerabilities (8.4%). A CWE is a label for the kind of mistake behind a flaw.
Weakness labels on 10 or more vulnerabilities
| Label | Official name | Vulnerabilities | Share of 536 |
|---|---|---|---|
| CWE-287 | Improper Authentication | 45 | 8.4% |
| CWE-20 | Improper Input Validation | 26 | 4.9% |
| CWE-798 | Use of Hard-coded Credentials | 23 | 4.3% |
| CWE-319 | Cleartext Transmission of Sensitive Information | 18 | 3.4% |
| CWE-284 | Improper Access Control | 18 | 3.4% |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 14 | 2.6% |
| CWE-259 | Use of Hard-coded Password | 13 | 2.4% |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 12 | 2.2% |
| CWE-306 | Missing Authentication for Critical Function | 12 | 2.2% |
| CWE-522 | Insufficiently Protected Credentials | 11 | 2.1% |
| CWE-787 | Out-of-bounds Write | 11 | 2.1% |
| CWE-311 | Missing Encryption of Sensitive Data | 10 | 1.9% |
| CWE-125 | Out-of-bounds Read | 10 | 1.9% |
Source: The PenTest Index analysis of weakness labels printed in CISA ICS medical advisories; names from MITRE CWE. Checked October 9, 2026 (UTC).
A caution for anyone charting these. 167 of the 536 (31.2%) carry a label MITRE discourages or prohibits for mapping a specific flaw. Reasons include labels that are too broad, categories rather than weaknesses, and labels often confused with an attack's impact. That is why this page leads with groups.
Which medical devices and makers have the most vulnerabilities?
Imaging software has the most advisories: 43 of 192 (22.4%). Infusion pumps, medication and supply systems come next with 26, and patient monitors have 25. More advisories does not mean more danger.
A long list can mean more people are looking. It can also mean the maker reports its own flaws.
Which device types are named most?
Imaging machines have the highest share of high or critical flaws, at 76.6% (36 of 47). Heart devices (22.9%) and diabetes devices (19.4%) have the lowest.
CISA medical advisories and severity by device group
| Device group | Advisories | Share of 192 | Vulnerabilities with a score | Rated high or critical |
|---|---|---|---|---|
| Imaging software (PACS and DICOM) | 43 | 22.4% | 94 | 51 (54.3%) |
| Infusion pumps, medication and supply systems | 26 | 13.5% | 91 | 38 (41.8%) |
| Patient monitors, ECG and vital signs | 25 | 13.0% | 61 | 20 (32.8%) |
| Hospital software, apps and device connectivity | 20 | 10.4% | 48 | 33 (68.8%) |
| Surgery, therapy, shared parts and other | 18 | 9.4% | 61 | 36 (59.0%) |
| Heart implants, programmers and home monitors | 14 | 7.3% | 35 | 8 (22.9%) |
| Lab and diagnostic instruments | 14 | 7.3% | 35 | 17 (48.6%) |
| Imaging machines | 14 | 7.3% | 47 | 36 (76.6%) |
| Diabetes devices and apps | 10 | 5.2% | 31 | 6 (19.4%) |
| Breathing, sleep and anesthesia | 8 | 4.2% | 19 | 9 (47.4%) |
Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. The ten groups are our own sorting, and every row is in the data file so you can sort them your way. A vulnerability listed in two groups is counted in each. We use the same selected score for that CVE in both groups. For CVE-2017-0143, the imaging-software row uses the 8.1 score in Baxter's ICSMA-20-170-01; Philips' ICSMA-18-058-02 gives only a range. Using only scores printed in imaging advisories would give 50 high or critical flaws out of 93 scored (53.8%).
Two notes keep this table fair.
- One GE advisory holds 23 of the 47 imaging machine flaws, all scored 9.8. Without it, imaging machines are 13 of 24 (54.2%).
- Heart and diabetes devices have more limited attack paths in many of these scores. For 30 of the 35 heart-device flaws and 19 of the 31 diabetes-device flaws, the attacker needs adjacent-network or physical access. Attack path is one part of the score; this table does not prove why the groups differ.
Which makers are named most?
Four makers are named in almost half of all advisories. Philips, BD, Medtronic and Baxter account for 88 of 192 (45.8%). This is not a ranking of who is worst.
The eight makers named in the most CISA medical advisories
| Maker | Advisories | Share of 192 | CVE listings | Advisories crediting only the maker |
|---|---|---|---|---|
| Philips | 41 | 21.4% | 121 | 15 |
| BD | 23 | 12.0% | 46 | 16 |
| Medtronic | 15 | 7.8% | 33 | 5 |
| Baxter | 9 | 4.7% | 34 | 7 |
| Santesoft | 7 | 3.6% | 12 | 0 |
| GE HealthCare | 6 | 3.1% | 36 | 0 |
| B. Braun | 5 | 2.6% | 21 | 0 |
| MicroDicom | 5 | 2.6% | 8 | 0 |
Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Each advisory is counted under one maker. Maker names are tidied by us.
- There are 74 maker, vendor or software-project names in all, and 53 appear once. This includes software projects such as pydicom; it is not a count of 74 device manufacturers.
- Hillrom is counted on its own (3 advisories). Baxter completed its purchase of Hillrom in December 2021.
- BD is the only party credited in 16 of its 23 advisories. A maker that reports its own flaws will have a longer list.
Who finds or reports medical device vulnerabilities?
Mostly outside or anonymous reporters. Of the 192 advisories, 143 (74.5%) credit an outside or anonymous reporter, such as a security researcher or a hospital. The other 49 (25.5%) credit only the maker. An anonymous report does not tell us the reporter's affiliation.
In the versions we checked, 163 of 192 advisories (84.9%) used one of two narrower statements: no known public exploits, or no known public exploitation. Those statements do not mean the same thing.
Exploit wording on the advisory pages checked
| What the checked advisory says | Advisories | Share of 192 |
|---|---|---|
| No known public exploits (older wording) | 104 | 54.2% |
| No known public exploitation reported (newer wording) | 59 | 30.7% |
| Public exploit code said to be available | 21 | 10.9% |
| Nothing stated | 5 | 2.6% |
| Other wording | 3 | 1.6% |
Source: The PenTest Index reading of the exploit statement in each CISA ICS medical advisory, checked October 9, 2026 (UTC). The analysis cutoff is October 8, 2026. "Public exploit code" means code that could be used in an attack was public. It does not mean the device was attacked.
How did the list change after 2023?
The list looks different now. In 2016 to 2022, the four big makers were named in 57.7% of advisories and imaging software was 10.0%. In 2023 to 2026, the four makers fell to 21.0% and imaging software rose to 48.4%.
Before and after 2023
| Measure | 2016 to 2022 | 2023 to 2026 | 2025 to 2026 only |
|---|---|---|---|
| Advisories | 130 | 62 | 39 |
| About imaging software | 13 (10.0%) | 30 (48.4%) | 21 (53.8%) |
| Naming Philips, BD, Medtronic or Baxter | 75 (57.7%) | 13 (21.0%) | 2 (5.1%) |
| Crediting only the device maker | 40 (30.8%) | 9 (14.5%) | 0 (0.0%) |
Source: The PenTest Index analysis of CISA ICS medical advisories, October 8, 2026. Device groups are our own sorting.
Of the 32 maker, vendor or project names in 2025 and 2026, 23 did not appear in the 2016–2024 medical-series advisories. The data shows the change. It does not explain it.
Which FDA cybersecurity alerts match a CISA advisory?
Eleven of the FDA's 18 cybersecurity safety notices match a CISA medical advisory in this dataset. Three more match a CISA advisory outside the medical series, three match broader CISA alerts, and one is general advice.
The FDA's table runs from June 13, 2013 to January 30, 2025. Nothing newer was in it when checked on October 9, 2026 (UTC).
FDA cybersecurity safety communications matched to CISA advisories
| FDA date | FDA notice (short name) | Matching CISA record | In our 192? | CVEs in the CISA record |
|---|---|---|---|---|
| Jan 30, 2025 | Contec and Epsimed patient monitors | ICSMA-25-030-01 | Yes | 4 |
| Sep 20, 2022 | Medtronic MiniMed 600 series insulin pumps | ICSMA-22-263-01 | Yes | 1 |
| Jun 2, 2022 | Illumina Local Run Manager | ICSA-22-153-02 | No (not in the medical series) | 5 |
| Mar 8, 2022 | PTC Axeda agent (shared software) | ICSA-22-067-01 | No (not in the medical series) | 7 |
| Dec 22, 2021 | Fresenius Kabi Agilia Connect infusion system | ICSMA-21-355-01 | Yes | 13 |
| Dec 17, 2021 | Apache Log4j (shared software) | CISA alert, Dec 10, 2021 | No | 1 |
| Aug 17, 2021 | BlackBerry QNX (shared software) | AA21-229A | No | 1 |
| Mar 3, 2020 | SweynTooth (shared Bluetooth software) | ICS-ALERT-20-063-01 | No | 12 |
| Jan 23, 2020 | GE Healthcare central stations and telemetry servers | ICSMA-20-023-01 | Yes | 6 |
| Oct 1, 2019 | URGENT/11 (shared network software) | ICSMA-19-274-01 | Yes | 11 |
| Jun 27, 2019 | Medtronic MiniMed insulin pumps | ICSMA-19-178-01 | Yes | 1 |
| Mar 21, 2019 | Medtronic implantable heart devices, programmers and home monitors | ICSMA-19-080-01 | Yes | 2 |
| Oct 11, 2018 | Medtronic heart device programmers | ICSMA-18-058-01 | Yes | 3 |
| Apr 17, 2018 | Abbott (formerly St. Jude Medical) implantable heart devices | ICSMA-18-107-01 | Yes | 2 |
| Aug 29, 2017 | Abbott (formerly St. Jude Medical) pacemakers | ICSMA-17-241-01 | Yes | 3 |
| Jan 9, 2017 | St. Jude Medical heart devices and Merlin@home transmitter | ICSMA-17-009-01A | Yes | 1 |
| May 13, 2015 | Hospira LifeCare PCA infusion pumps | ICSA-15-125-01B | No (before the medical series) | 7 |
| Jun 13, 2013 | Cybersecurity for medical devices and hospital networks | None (general advice) | No | Not applicable |
Source: FDA, Cybersecurity Safety Communications and Other Alerts, checked October 9, 2026 (UTC); matched by The PenTest Index to CISA advisories and CISA's published advisory files. "CVEs" counts ID numbers in the CISA record. It does not count attacks, patients or devices. The FDA's URGENT/11 press release links the medical advisory; the same flaws also appeared in ICSA-19-211-01. The Log4j and QNX counts cover the specific linked alerts, not every flaw in those software families.
Three things a writer should know before citing the FDA's table.
- It is not a full history. The FDA sent a letter about Illumina's Universal Copy Service on April 27, 2023. That letter is not in the table. CISA's matching advisory, ICSMA-23-117-01, is in our dataset.
- Advice changes after the first warning. The FDA updated its Contec notice on July 2, 2025 to say a patch exists. The FDA says the patch "fully removes networking functionality" and that patients and caregivers "should not install the software patch as the installation requires specialized expertise." Older text lower on the same page still says no patch is available.
- Others have studied these 18. A March 2026 paper in Frontiers in Digital Health analyzed the same notices. Our part is the match to CISA's records.
How do I look up a medical device, maker or CVE?
Search the table below by maker, product or CVE number. It holds all 192 advisories, and each row links to CISA's own page. No match means this list has no record. It does not mean a product is safe.
Showing 192 of 192 advisories
| Advisory ID | Product | Maker | Device group | CVE count | Top CVSS v3 | Known exploited CVEs | Credited | Source URL | Check date |
|---|---|---|---|---|---|---|---|---|---|
| ICSMA-26-253-02 | Orthanc DICOM Server1 CVE listing
| Orthanc | Imaging software (PACS and DICOM) | 1 | 8.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-253-01 | NextGen Healthcare Mirth Connect3 CVE listings
| NextGen Healthcare | Hospital software, apps and device connectivity | 3 | 8.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-225-01 | Flow Neuroscience FL-1001 CVE listing
| Flow Neuroscience | Surgery, therapy, shared parts and other | 1 | 8.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-223-02 | Pulsetto Vagus Nerve Stimulator (Update A)1 CVE listing
| Pulsetto | Surgery, therapy, shared parts and other | 1 | 8.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-223-01 | Mira Hormone Monitor, Mira Android App8 CVE listings
| Quanovate Tech (Mira) | Lab and diagnostic instruments | 8 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-218-01 | Medixant RadiAnt DICOM1 CVE listing
| Medixant | Imaging software (PACS and DICOM) | 1 | 4.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-216-01 | Thermo Fisher Applied Biosystems Genetic Analyzers1 CVE listing
| Thermo Fisher | Lab and diagnostic instruments | 1 | 8.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-181-01 | OFFIS DCMTK Toolkit5 CVE listings
| OFFIS | Imaging software (PACS and DICOM) | 5 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-176-02 | OHIF Viewers DICOM1 CVE listing
| Open Health Imaging Foundation | Imaging software (PACS and DICOM) | 1 | 8.2 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-176-01 | pydicom pynetdicom Library1 CVE listing
| pydicom | Imaging software (PACS and DICOM) | 1 | 9.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-169-01 | Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT2 CVE listings
| Apollo Pharmacy | Diabetes devices and apps | 2 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-148-01 | Fourth Frontier Frontier X Mobile Application, Frontier X21 CVE listing
| Fourth Frontier | Patient monitors, ECG and vital signs | 1 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-146-01 | Eppendorf BioFlo 3201 CVE listing
| Eppendorf | Lab and diagnostic instruments | 1 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-083-01 | Grassroots DICOM (GDCM)1 CVE listing
| Grassroots DICOM | Imaging software (PACS and DICOM) | 1 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-26-041-01 | ZOLL ePCR IOS Mobile Application1 CVE listing
| ZOLL | Hospital software, apps and device connectivity | 1 | 5.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-364-01 | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs (Update B)1 CVE listing
| WHILL | Surgery, therapy, shared parts and other | 1 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-345-02 | Varex Imaging Panoramic Dental Imaging Software1 CVE listing
| Varex Imaging | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-345-01 | Grassroots DICOM (GDCM)1 CVE listing
| Grassroots DICOM | Imaging software (PACS and DICOM) | 1 | 6.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-336-01 | Mirion Medical EC2 Software NMIS BioDose5 CVE listings
| Mirion Medical | Hospital software, apps and device connectivity | 5 | 8.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-301-01 | Vertikal Systems Hospital Manager Backend Services2 CVE listings
| Vertikal Systems | Hospital software, apps and device connectivity | 2 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-296-01 | NIHON KOHDEN Central Monitor CNS-62011 CVE listing
| NIHON KOHDEN | Patient monitors, ECG and vital signs | 1 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-294-01 | Oxford Nanopore Technologies MinKNOW3 CVE listings
| Oxford Nanopore Technologies | Lab and diagnostic instruments | 3 | 8.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-233-01 | FUJIFILM Healthcare Americas Synapse Mobility1 CVE listing
| Fujifilm | Imaging software (PACS and DICOM) | 1 | 4.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-224-01 | Santesoft Sante PACS Server5 CVE listings
| Santesoft | Imaging software (PACS and DICOM) | 5 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-205-01 | Medtronic MyCareLink Patient Monitor (Update A)6 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 6 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-198-01 | Panoramic Corporation Digital Imaging Software1 CVE listing
| Panoramic | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-160-01 | MicroDicom DICOM Viewer1 CVE listing
| MicroDicom | Imaging software (PACS and DICOM) | 1 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-148-01 | Santesoft Sante DICOM Viewer Pro1 CVE listing
| Santesoft | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-128-01 | Pixmeo OsiriX MD3 CVE listings
| Pixmeo | Imaging software (PACS and DICOM) | 3 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-121-01 | MicroDicom DICOM Viewer2 CVE listings
| MicroDicom | Imaging software (PACS and DICOM) | 2 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-100-01 | INFINITT Healthcare INFINITT PACS3 CVE listings
| INFINITT Healthcare | Imaging software (PACS and DICOM) | 3 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-079-01 | Santesoft Sante DICOM Viewer Pro1 CVE listing
| Santesoft | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-072-01 | Philips Intellispace Cardiovascular (ISCV)2 CVE listings
| Philips | Imaging software (PACS and DICOM) | 2 | 7.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-058-01 | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application7 CVE listings
| Dario Health | Diabetes devices and apps | 7 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-051-01 | Medixant RadiAnt DICOM Viewer1 CVE listing
| Medixant | Imaging software (PACS and DICOM) | 1 | 5.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-044-01 | Qardio Heart Health IOS and Android Application and QardioARM A1003 CVE listings
| Qardio | Patient monitors, ECG and vital signs | 3 | 7.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-037-02 | Orthanc Server1 CVE listing
| Orthanc | Imaging software (PACS and DICOM) | 1 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-037-01 | MicroDicom DICOM Viewer1 CVE listing
| MicroDicom | Imaging software (PACS and DICOM) | 1 | 5.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-25-030-01 | Contec Health CMS8000 Patient Monitor (Update A)4 CVE listings
| Contec Health | Patient monitors, ECG and vital signs | 4 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-354-01 | Ossur Mobile Logic Application3 CVE listings
| Ossur | Surgery, therapy, shared parts and other | 3 | 4.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-352-01 | BD Diagnostic Solutions Products (Update A)1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 8.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-24-319-01 | Baxter Life2000 Ventilation System9 CVE listings
| Baxter | Breathing, sleep and anesthesia | 9 | 10.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-24-254-01 | BPL Medical Technologies PWS-01-BT and BPL Be Well Android Application1 CVE listing
| BPL Medical Technologies | Patient monitors, ECG and vital signs | 1 | 4.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-249-01 | Baxter Connex Health Portal2 CVE listings
| Baxter | Hospital software, apps and device connectivity | 2 | 10.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-24-200-01 | Philips Vue PACS (Update A)2 CVE listings
| Philips | Imaging software (PACS and DICOM) | 2 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-163-01 | MicroDicom DICOM Viewer2 CVE listings
| MicroDicom | Imaging software (PACS and DICOM) | 2 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-151-02 | Baxter Welch Allyn Connex Spot Monitor1 CVE listing
| Baxter | Patient monitors, ECG and vital signs | 1 | 7.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-151-01 | Baxter Welch Allyn Configuration Tool1 CVE listing
| Baxter | Hospital software, apps and device connectivity | 1 | 9.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-24-065-01 | Santesoft Sante FFT Imaging1 CVE listing
| Santesoft | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-060-01 | MicroDicom DICOM Viewer2 CVE listings
| MicroDicom | Imaging software (PACS and DICOM) | 2 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-058-01 | Santesoft Sante DICOM Viewer Pro1 CVE listing
| Santesoft | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-24-023-01 | Orthanc Osimis DICOM Web Viewer1 CVE listing
| Orthanc | Imaging software (PACS and DICOM) | 1 | 7.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-331-01 | BD FACSChorus7 CVE listings
| BD | Lab and diagnostic instruments | 7 | 5.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-285-02 | Santesoft Sante FFT Imaging1 CVE listing
| Santesoft | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-285-01 | Santesoft Sante DICOM Viewer Pro2 CVE listings
| Santesoft | Imaging software (PACS and DICOM) | 2 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-248-01 | Softneta MedDream PACS2 CVE listings
| Softneta | Imaging software (PACS and DICOM) | 2 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-194-01 | BD Alaris System with Guardrails Suite MX (Update A)8 CVE listings
| BD | Infusion pumps, medication and supply systems | 8 | 8.2 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-23-180-01 | Medtronic Paceart Optima System1 CVE listing
| Medtronic | Heart implants, programmers and home monitors | 1 | 9.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-23-117-01 | Illumina Universal Copy Service2 CVE listings
| Illumina | Lab and diagnostic instruments | 2 | 10.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-23-103-01 | B. Braun Battery Pack SP with Wi-Fi1 CVE listing
| B. Braun | Infusion pumps, medication and supply systems | 1 | 5.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-23-061-01 | Medtronic Micro Clinician and InterStim Apps1 CVE listing
| Medtronic | Surgery, therapy, shared parts and other | 1 | 6.4 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-23-047-01 | BD Alaris Infusion Central (Update A)1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 7.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-335-01 | BD BodyGuard Pumps1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 5.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-298-01 | AliveCor KardiaMobile2 CVE listings
| AliveCor | Patient monitors, ECG and vital signs | 2 | 5.2 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-277-01 | BD Totalys MultiProcessor1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 6.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-263-01 | Medtronic NGP 600 Series Insulin Pumps1 CVE listing
| Medtronic | Diabetes devices and apps | 1 | 4.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-251-01 | Baxter Sigma Spectrum Infusion Pump (Update A)4 CVE listings
| Baxter | Infusion pumps, medication and supply systems | 4 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-244-01 | Contec Health CMS8000 Patient Monitor (Update A)5 CVE listings
| Contec Health | Patient monitors, ECG and vital signs | 5 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-174-01 | OFFIS DCMTK3 CVE listings
| OFFIS | Imaging software (PACS and DICOM) | 3 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-167-01 | Hillrom Medical Device Management2 CVE listings
| Hillrom | Patient monitors, ECG and vital signs | 2 | 7.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-151-02 | BD Synapsys1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 5.7 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-151-01 | BD Pyxis1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 8.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-095-01 | LifePoint Informatics Patient Portal1 CVE listing
| LifePoint Informatics | Hospital software, apps and device connectivity | 1 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-088-01 | Philips e-Alert1 CVE listing
| Philips | Imaging machines | 1 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-22-062-02 | BD Viper LT1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 8.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-062-01 | BD Pyxis1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 7.0 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-22-006-01 | Philips Engage Software1 CVE listing
| Philips | Hospital software, apps and device connectivity | 1 | 2.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-355-01 | Fresenius Kabi Agilia Connect Infusion System (Update A)13 CVE listings
| Fresenius Kabi | Infusion pumps, medication and supply systems | 13 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-343-01 | Hillrom Welch Allyn Cardio Products1 CVE listing
| Hillrom | Patient monitors, ECG and vital signs | 1 | 8.1 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-21-322-02 | Philips Patient Information Center iX (PIC iX) and Efficia CM Series (Update A)3 CVE listings
| Philips | Patient monitors, ECG and vital signs | 3 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-322-01 | Philips IntelliBridge EC 40 and EC 80 Hub2 CVE listings
| Philips | Hospital software, apps and device connectivity | 2 | 8.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-313-01 | Philips MRI 1.5T and 3T (Update A)3 CVE listings
| Philips | Imaging machines | 3 | 6.2 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-308-01 | Philips Tasy EMR2 CVE listings
| Philips | Hospital software, apps and device connectivity | 2 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-294-01 | B. Braun Infusomat Space Large Volume Pump (Update A)5 CVE listings
| B. Braun | Infusion pumps, medication and supply systems | 5 | 9.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-273-01 | Boston Scientific Zoom Latitude5 CVE listings
| Boston Scientific | Heart implants, programmers and home monitors | 5 | 6.9 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-215-01 | Swisslog Healthcare Translogic PTS8 CVE listings
| Swisslog Healthcare | Surgery, therapy, shared parts and other | 8 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-196-01 | Ypsomed mylife4 CVE listings
| Ypsomed | Diabetes devices and apps | 4 | 6.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-187-01 | Philips Vue PACS (Update C)17 CVE listings
| Philips | Imaging software (PACS and DICOM) | 17 | 9.8 | 1 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-175-01 | Philips Interoperability Solution XDS1 CVE listing
| Philips | Hospital software, apps and device connectivity | 1 | 3.7 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-21-161-01 | ZOLL Defibrillator Dashboard6 CVE listings
| ZOLL | Hospital software, apps and device connectivity | 6 | 9.9 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-152-01 | Hillrom Medical Device Management (Update C)2 CVE listings
| Hillrom | Patient monitors, ECG and vital signs | 2 | 5.9 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-084-01 | Philips Gemini PET/CT Family1 CVE listing
| Philips | Imaging machines | 1 | 2.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-047-01 | Hamilton-T13 CVE listings
| Hamilton Medical | Breathing, sleep and anesthesia | 3 | 4.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-019-01 | Philips Interventional Workstations1 CVE listing
| Philips | Imaging machines | 1 | 6.5 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-21-012-01 | SOOIL Dana Diabecare RS Products9 CVE listings
| SOOIL Developments | Diabetes devices and apps | 9 | 7.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-21-007-01 | Innokas Yhtymä Oy Vital Signs Monitor2 CVE listings
| Innokas Yhtymä Oy | Patient monitors, ECG and vital signs | 2 | 5.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-345-01 | Medtronic MyCareLink Smart3 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 3 | 8.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-343-01 | GE Healthcare Imaging and Ultrasound Products2 CVE listings
| GE HealthCare | Imaging machines | 2 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-317-01 | BD Alaris 8015 PC Unit and BD Alaris Systems Manager1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-296-02 | B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus (Update A)11 CVE listings
| B. Braun | Infusion pumps, medication and supply systems | 11 | 7.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-296-01 | B. Braun OnlineSuite3 CVE listings
| B. Braun | Infusion pumps, medication and supply systems | 3 | 8.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-261-01 | Philips Clinical Collaboration Platform5 CVE listings
| Philips | Imaging software (PACS and DICOM) | 5 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-254-01 | Philips Patient Monitoring Devices (Update C)8 CVE listings
| Philips | Patient monitors, ECG and vital signs | 8 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-233-01 | Philips SureSigns VS43 CVE listings
| Philips | Patient monitors, ECG and vital signs | 3 | 6.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-212-01 | Philips DreamMapper1 CVE listing
| Philips | Breathing, sleep and anesthesia | 1 | 5.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-196-01 | Capsule Technologies SmartLinx Neuron 2 (Update A)1 CVE listing
| Capsule Technologies | Hospital software, apps and device connectivity | 1 | 7.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-184-01 | OpenClinic GA (Update B)14 CVE listings
| OpenClinic GA (open source) | Hospital software, apps and device connectivity | 14 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-177-01 | Philips Ultrasound Systems1 CVE listing
| Philips | Imaging machines | 1 | 3.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-170-06 | BD Alaris PCU (Update A)1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 5.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-170-05 | BIOTRONIK CardioMessenger II5 CVE listings
| BIOTRONIK | Heart implants, programmers and home monitors | 5 | 4.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-170-04 | Baxter Sigma Spectrum Infusion Pumps (Update B)6 CVE listings
| Baxter | Infusion pumps, medication and supply systems | 6 | 8.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-170-03 | Baxter Phoenix Hemodialysis Delivery System (Update A)1 CVE listing
| Baxter | Surgery, therapy, shared parts and other | 1 | 7.5 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-170-02 | Baxter PrismaFlex and PrisMax (Update B)3 CVE listings
| Baxter | Surgery, therapy, shared parts and other | 3 | 7.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-170-01 | Baxter ExactaMix (Update A)7 CVE listings
| Baxter | Infusion pumps, medication and supply systems | 7 | 8.1 | 1 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-163-01 | Philips IntelliBridge Enterprise IBE1 CVE listing
| Philips | Hospital software, apps and device connectivity | 1 | 2.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-091-01 | BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 6.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-20-079-01 | Insulet Omnipod1 CVE listing
| Insulet | Diabetes devices and apps | 1 | 7.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-049-02 | GE Healthcare Ultrasound Products (Update A)2 CVE listings
| GE HealthCare | Imaging machines | 2 | 8.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-049-01 | Spacelabs Xhibit Telemetry Receiver (XTR)1 CVE listing
| Spacelabs | Patient monitors, ECG and vital signs | 1 | 9.8 | 1 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-20-023-01 | GE CARESCAPE, ApexPro, and Clinical Information Center systems6 CVE listings
| GE HealthCare | Patient monitors, ECG and vital signs | 6 | 10.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-353-01 | Philips Veradius Unity, Pulsera, and Endura Dual WAN Routers1 CVE listing
| Philips | Imaging machines | 1 | 5.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-318-01 | Philips IntelliBridge EC40/80 (Update A)1 CVE listing
| Philips | Hospital software, apps and device connectivity | 1 | 6.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-311-02 | Medtronic Valleylab FT10 and FX84 CVE listings
| Medtronic | Surgery, therapy, shared parts and other | 4 | 9.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-19-311-01 | Medtronic Valleylab FT10 and LS102 CVE listings
| Medtronic | Surgery, therapy, shared parts and other | 2 | 4.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-19-297-01 | Philips IntelliSpace Perinatal1 CVE listing
| Philips | Patient monitors, ECG and vital signs | 1 | 6.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-274-01 | Interpeak IPnet TCP/IP Stack (Update D)11 CVE listings
| Interpeak (IPnet; multiple RTOS vendors) | Surgery, therapy, shared parts and other | 11 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-255-01 | Philips IntelliVue WLAN2 CVE listings
| Philips | Patient monitors, ECG and vital signs | 2 | 6.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-248-01 | BD Pyxis (Update A)1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 7.6 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-19-241-02 | Philips HDI 4000 Ultrasound1 CVE listing
| Philips | Imaging machines | 1 | 3.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-241-01 | Change Healthcare McKesson and Horizon Cardiology1 CVE listing
| Change Healthcare | Imaging software (PACS and DICOM) | 1 | 7.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-192-01 | Philips Holter 2010 Plus1 CVE listing
| Philips | Patient monitors, ECG and vital signs | 1 | 1.9 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-19-190-01 | GE Aestiva and Aespire Anesthesia (Update A)1 CVE listing
| GE HealthCare | Breathing, sleep and anesthesia | 1 | 5.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-178-01 | Medtronic MiniMed 508 and Paradigm Series Insulin Pumps1 CVE listing
| Medtronic | Diabetes devices and apps | 1 | 7.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-164-01 | BD Alaris Gateway Workstation2 CVE listings
| BD | Infusion pumps, medication and supply systems | 2 | 10.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-120-01 | Philips Tasy EMR (Update A)2 CVE listings
| Philips | Hospital software, apps and device connectivity | 2 | 4.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-113-01 | Fujifilm FCR Capsula X/Carbon X2 CVE listings
| Fujifilm | Imaging machines | 2 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-080-01 | Medtronic Conexus Radio Frequency Telemetry Protocol (Update C)2 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 2 | 9.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-029-02 | BD FACSLyric (Update A)1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 6.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-19-029-01 | Stryker Medical Beds9 CVE listings
| Stryker | Surgery, therapy, shared parts and other | 9 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-19-022-01 | Dräger Infinity Delta3 CVE listings
| Dräger | Patient monitors, ECG and vital signs | 3 | 8.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-347-01 | Medtronic 9790, 2090 CareLink, and 29901 Encore Programmers1 CVE listing
| Medtronic | Heart implants, programmers and home monitors | 1 | 4.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-340-01 | Philips HealthSuite Health Android App1 CVE listing
| Philips | Hospital software, apps and device connectivity | 1 | 3.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-312-01 | Philips iSite and IntelliSpace PACS1 CVE listing
| Philips | Imaging software (PACS and DICOM) | 1 | 6.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-310-01 | Roche Diagnostics Point of Care Handheld Medical Devices (Update A)5 CVE listings
| Roche Diagnostics | Lab and diagnostic instruments | 5 | 8.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-277-02 | Change Healthcare PeerVue Web Server1 CVE listing
| Change Healthcare | Imaging software (PACS and DICOM) | 1 | 4.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-277-01 | Carestream Vue RIS1 CVE listing
| Carestream | Imaging software (PACS and DICOM) | 1 | 3.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-240-01 | Qualcomm Life Capsule1 CVE listing
| Qualcomm Life | Hospital software, apps and device connectivity | 1 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-235-01 | BD Alaris Plus1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 9.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-233-01 | Philips IntelliVue Information Center iX (Update B)1 CVE listing
| Philips | Patient monitors, ECG and vital signs | 1 | 5.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-228-01 | Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs (Update A)2 CVE listings
| Philips | Patient monitors, ECG and vital signs | 2 | 6.1 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-226-01 | Philips IntelliSpace Cardiovascular Vulnerabilities2 CVE listings
| Philips | Imaging software (PACS and DICOM) | 2 | 7.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-219-02 | Medtronic MiniMed MMT-500/MMT-503 Remote Controllers (Update A)2 CVE listings
| Medtronic | Diabetes devices and apps | 2 | 5.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-219-01 | Medtronic MyCareLink 24950 Patient Monitor (Update A)2 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 2 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-179-01 | Medtronic MyCareLink Patient Monitor2 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 2 | 6.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-165-01 | Natus Xltek NeuroWorks8 CVE listings
| Natus Medical | Surgery, therapy, shared parts and other | 8 | 10.0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-156-01 | Philips' IntelliVue Patient and Avalon Fetal Monitors3 CVE listings
| Philips | Patient monitors, ECG and vital signs | 3 | 8.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-144-01 | BeaconMedaes TotalAlert Scroll Medical Air Systems3 CVE listings
| BeaconMedaes | Surgery, therapy, shared parts and other | 3 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-142-01 | BD Kiestra and InoquIA Systems (Update A)2 CVE listings
| BD | Lab and diagnostic instruments | 2 | 6.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-137-02 | Philips EncoreAnywhere1 CVE listing
| Philips | Breathing, sleep and anesthesia | 1 | 5.9 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-137-01 | Medtronic N'Vision Clinician Programmer (Update A)2 CVE listings
| Medtronic | Surgery, therapy, shared parts and other | 2 | 6.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-128-01 | Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update B)2 CVE listings
| GE HealthCare | Surgery, therapy, shared parts and other | 2 | 7.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-123-01 | Philips Brilliance Computed Tomography (CT) System (Update A)3 CVE listings
| Philips | Imaging machines | 3 | 8.4 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-114-01 | BD Pyxis9 CVE listings
| BD | Infusion pumps, medication and supply systems | 9 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-107-02 | Biosense Webster Carto 3 System Vulnerabilities | Biosense Webster | Surgery, therapy, shared parts and other | 0 | 0 | Device maker only | CISA advisory | 2026-10-09 | |
| ICSMA-18-107-01 | Abbott Laboratories Defibrillator2 CVE listings
| Abbott | Heart implants, programmers and home monitors | 2 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-088-01 | Philips iSite/IntelliSpace PACS Vulnerabilities (Update A) | Philips | Imaging software (PACS and DICOM) | 0 | 0 | Device maker only | CISA advisory | 2026-10-09 | |
| ICSMA-18-086-01 | Philips Alice 6 Vulnerabilities (Update B)2 CVE listings
| Philips | Breathing, sleep and anesthesia | 2 | 5.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-058-02 | Philips Intellispace Portal ISP Vulnerabilities35 CVE listings
| Philips | Imaging software (PACS and DICOM) | 35 | 7.8 | 7 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-18-058-01 | Medtronic 2090 Carelink Programmer Vulnerabilities (Update C)3 CVE listings
| Medtronic | Heart implants, programmers and home monitors | 3 | 7.1 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-037-02 | GE Medical Devices Vulnerability23 CVE listings
| GE HealthCare | Imaging machines | 23 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-037-01 | Vyaire Medical CareFusion Upgrade Utility Vulnerability1 CVE listing
| Vyaire Medical | Breathing, sleep and anesthesia | 1 | 6.7 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-18-025-01 | Philips IntelliSpace Cardiovascular System Vulnerability1 CVE listing
| Philips | Imaging software (PACS and DICOM) | 1 | 6.7 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-332-01 | Ethicon Endo-Surgery Generator G11 Vulnerability1 CVE listing
| Ethicon Endo-Surgery | Surgery, therapy, shared parts and other | 1 | 4.8 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-318-01 | Philips IntelliSpace Cardiovascular System and Xcelera System Vulnerability1 CVE listing
| Philips | Imaging software (PACS and DICOM) | 1 | 7.2 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-292-01 | Boston Scientific ZOOM LATITUDE PRM Vulnerabilities2 CVE listings
| Boston Scientific | Heart implants, programmers and home monitors | 2 | 4.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-255-01 | Philips' IntelliView MX40 Patient Worn Monitor (WLAN) Vulnerabilities2 CVE listings
| Philips | Patient monitors, ECG and vital signs | 2 | 6.5 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-250-02A | Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump Vulnerabilities (Update A)8 CVE listings
| Smiths Medical | Infusion pumps, medication and supply systems | 8 | 9.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-250-01 | i-SENS, Inc. SmartLog Diabetes Management Software1 CVE listing
| i-SENS | Diabetes devices and apps | 1 | 7.3 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-241-01 | Abbott Laboratories’ Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI Pacemaker Vulnerabilities3 CVE listings
| Abbott | Heart implants, programmers and home monitors | 3 | 7.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-229-01 | Philips' DoseWise Portal Vulnerabilities2 CVE listings
| Philips | Imaging software (PACS and DICOM) | 2 | 9.1 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-227-01 | BMC Medical and 3B Medical Luna CPAP Machine1 CVE listing
| BMC Medical / 3B Medical | Breathing, sleep and anesthesia | 1 | 4.6 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-215-02 | Siemens Molecular Imaging Vulnerabilities4 CVE listings
| Siemens | Imaging machines | 4 | 9.8 | 1 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-215-01 | Siemens Molecular Imaging Vulnerabilities2 CVE listings
| Siemens | Imaging machines | 2 | 9.8 | 2 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-082-02 | B. Braun Medical SpaceCom Open Redirect Vulnerability1 CVE listing
| B. Braun | Infusion pumps, medication and supply systems | 1 | 5.4 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-082-01 | BD Kiestra PerformA and KLA Journal Service Applications Hard-Coded Passwords Vulnerability1 CVE listing
| BD | Lab and diagnostic instruments | 1 | 7.3 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-017-02 | BD Alaris 8015 PC Unit (Update B)2 CVE listings
| BD | Infusion pumps, medication and supply systems | 2 | 6.8 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-17-017-01 | BD Alaris 8000 Insufficiently Protected Credentials Vulnerability1 CVE listing
| BD | Infusion pumps, medication and supply systems | 1 | 4.9 | 0 | Device maker only | CISA advisory | 2026-10-09 |
| ICSMA-17-009-01A | St. Jude Merlin@home Transmitter Vulnerability (Update A)1 CVE listing
| St. Jude Medical | Heart implants, programmers and home monitors | 1 | 8.9 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-16-306-01 | Smiths Medical CADD-Solis Medication Safety Software Vulnerabilities2 CVE listings
| Smiths Medical | Infusion pumps, medication and supply systems | 2 | 9.9 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-16-279-01 | Animas OneTouch Ping Insulin Pump Vulnerabilities3 CVE listings
| Animas | Diabetes devices and apps | 3 | 6.5 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
| ICSMA-16-196-01 | Philips Xper-IM Connect Vulnerabilities | Philips | Hospital software, apps and device connectivity | 0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 | |
| ICSMA-16-089-01 | CareFusion Pyxis SupplyStation System Vulnerabilities | BD | Infusion pumps, medication and supply systems | 0 | 0 | Outside or anonymous reporter credited | CISA advisory | 2026-10-09 |
Source: The CISA advisory source URL and check date appear in each row.
Where do the numbers everyone quotes come from?
Mostly from security companies, not from the government. The best-known figure, "6.2 vulnerabilities per medical device", traces to a February 7, 2018 vendor blog post with no sample, dates or method. The FBI printed it in 2022 without naming the research firm.
The numbers people repeat, and where each one started
| The number | What the original says | Who said it first, and when | What it really counts | Safe to quote? |
|---|---|---|---|---|
| "6.2 vulnerabilities per medical device" | "Sensato has found an average of 6.2 vulnerabilities per medical device." | Sensato blog post, February 7, 2018 (earliest we found) | The post gives no sample, observation dates or method. | No |
| "53% of connected medical devices have a known critical vulnerability" | "53% of connected medical devices and other IoT devices in hospitals have a known critical vulnerability." | Cynerio press release, January 19, 2022 | Medical devices and other connected devices, at Cynerio's own customers | Only with Cynerio's name, the year and "and other IoT devices" |
| "More than 40% of medical devices are end-of-life" | The 2018 post says "60 percent of devices are at end-of-life stage." | MedTech Dive, December 1, 2021, crediting Sensato; then the FBI in 2022 | The cited versions say 60% and more than 40%. Those claims can both be true, but neither gives a sampling method. | No |
| "75% of infusion pumps are vulnerable" | 75% of more than 200,000 pumps "had known security gaps", meaning a known vulnerability "and/or" another security alert | Unit 42, Palo Alto Networks, March 2, 2022 | Pumps with a vulnerability or an alert. Not only CVEs. | Yes, as "known security gaps" in Unit 42's March 2022 report and pump sample |
| "99% of hospitals have devices with exploited flaws" | "9% of IoMT devices contain confirmed KEVs in their systems, impacting 99% of organizations." | Claroty, March 26, 2025 | 99% is organizations (of 351). The device share is 9%. | Yes, with Claroty, its March 2025 report, sample and unit |
| "993 medical device vulnerabilities" | "993 vulnerabilities were found in 2023 (a 59% increase from 2022) spanning 966 healthcare products" | Health-ISAC, Finite State and Securin, 2023 | Products from 117 vendors, including healthcare software. The report says software applications hold 64%. | Yes, as the report's 2023 healthcare-product findings; not 993 newly disclosed device CVEs |
Source: each linked original, checked October 9, 2026 (UTC). Quoted words are copied from those sources; the rest of the table explains their scope.
Here is where "6.2" appears. A 2018 vendor blog post. A 2021 trade article that names Sensato. A 2022 FBI notice that calls it "a research report in 2021" by "a cybersecurity firm" and names no one. A 2023 GAO report that cites the FBI. The FBI does not identify its 2021 source, so we cannot prove that step in the chain. The same vendor figure now reads like a government fact.
Why do the numbers disagree so much?
Because they answer three different questions. One counts flaws, one counts devices, and one counts attacks.
Three questions, three kinds of answer
| The question | Who can answer it | A real answer |
|---|---|---|
| How many flaws have been found? | CISA's advisories | 536, in 192 advisories (The PenTest Index analysis, October 2026) |
| How many devices in hospitals carry a known flaw? | Companies that scan hospital networks | Claroty, March 2025: 9% of the connected medical devices it analyzed carried a known exploited flaw |
| Which named flaws have evidence of real attacks in CISA's catalog? | CISA's exploited list | 12 of the 536 (The PenTest Index analysis, October 2026) |
Source: The PenTest Index analysis and the Claroty press release linked above, checked October 9, 2026 (UTC).
Units trip people up most. Claroty reported its riskiest mix (a known exploited flaw tied to ransomware, plus an insecure internet connection) in 1% of devices but 89% of organizations. Both are right. One hospital can own thousands of devices, and it takes only one to count the hospital.
The same report shows how much device type matters. It puts that riskiest mix at 8% of imaging systems and 0.5% of patient devices in its sample.
What do CVE, KEV and CVSS mean?
They do three different jobs. A CVE names a flaw, KEV says a flaw has been used in real attacks, and CVSS scores how bad a flaw could be.
Terms that get mixed up
| Term | Plain meaning | What it does not tell you |
|---|---|---|
| CVE | The public ID for one disclosed flaw | How many devices have it |
| KEV | CISA's list of flaws with reliable evidence of real attacks | That your device was attacked |
| CVSS base score | A 0 to 10 score for how severe the flaw is | The risk at your hospital, or to a patient |
| CWE | A label for the kind of mistake behind the flaw | How easy the flaw is to use |
| Advisory | A notice about one or more flaws | That there is only one flaw, or any attack |
| Patch | A software change meant to fix a flaw | That every device in use got it |
Source: definitions from CISA, FIRST and MITRE, put in plain words by The PenTest Index.
Does the FDA require penetration testing for medical devices?
The law does not name penetration testing, but the FDA's guidance recommends it. Section 524B applies to qualifying FDA applications or submissions for "cyber devices" filed on or after March 29, 2023. It requires a security plan, a patching process and a list of software parts. The FDA's guidance, dated February 3, 2026, lists five things a penetration test report should include.
A penetration test is when trusted experts try to break into a product the way a real attacker would, so the maker can fix what they find.
The law and the guidance, side by side
| The law | The FDA's guidance | |
|---|---|---|
| What it is | Section 524B of the Federal Food, Drug, and Cosmetic Act | "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions" |
| Date | In force March 29, 2023 | Issued February 3, 2026. It replaces the June 27, 2025 version. |
| Force | Required for qualifying premarket applications or submissions for "cyber devices," including device changes that need a new submission | Recommendations are nonbinding; laws cited in the guidance still apply. The FDA says "should" means "suggested or recommended, but not required." |
| What it asks for | A plan to find and fix flaws after sale. Processes that keep the device secure, with updates and patches. A software bill of materials (SBOM), which is a list of the software parts inside. | Security testing, including penetration testing, and the test report itself. |
Source: FDA, Cybersecurity and the premarket cybersecurity guidance, checked October 9, 2026 (UTC). A "cyber device" has software and technology validated, installed or authorized by its sponsor, can connect to the internet, and could be open to cyber threats. The sponsor is the person or company making the FDA submission. Read the FDA's exact definition and submission rules. The guidance also covers devices with software, firmware or programmable logic that do not connect to a network.
The FDA says penetration test reports "should be provided and include the following elements":
- Independence and technical expertise of testers
- Scope of testing
- Duration of testing
- Testing methods employed
- Test results, findings, and observations
Three more lines from the same guidance tie back to the data on this page.
- On exploited flaws: vulnerabilities in CISA's Known Exploited Vulnerabilities Catalog "should be designed out of the device, as they are already being exploited." All 12 in this dataset came in through outside software.
- On passwords: makers should test for credentials that are "'hardcoded,' default, easily guessed, and easily compromised." Forty-two flaws here concern hard-coded or default passwords and keys.
- On timing: after release, cybersecurity testing "should be performed at regular intervals commensurate with the risk (e.g., annually)." Annual testing is an example based on risk, not a rule requiring every device to have a yearly penetration test.
One thing may confuse a careful reader. On October 9, 2026 (UTC), the FDA's own cybersecurity page still showed the June 27, 2025 date for this guidance. The PDF's cover says February 3, 2026.
If your device also has a web app or API, you can compare web and API penetration testing offers by the prices and scope they publish.
What should you do with a medical device vulnerability notice?
Match the notice to your exact product and software version first, then follow the maker's current instructions. Of 192 advisories, 68 show a later revision date than their number, so the first version you read may not be the last word.
If you make a device
- Check your software parts list against CISA's exploited list. All 12 known exploited flaws here came in through outside software.
- Test how the product checks identities. More than one in four flaws here is an authentication flaw.
- Plan for a penetration test report that covers the FDA's five items.
If you run devices in a hospital
- Look up your devices in the table above, then open CISA's page for each.
- Ask each maker for its software parts list and its patch plan.
- Work with the team that owns clinical safety before you change a device that is in use.
If you use one of these devices yourself
- This page is not medical advice.
- Follow your device maker's patch instructions. Do not try unofficial fixes you find online. Ask your care team if you are unsure. The FDA's plain-language guide is a good place to start.
Say you are a small device maker with a connected glucose meter and an FDA filing next spring. You would want a tester who can show independence, a clear scope, how long the test ran, the methods, and the findings. Those are the FDA's five items.
Getting ready to buy a penetration test for a device? Find My PenTest Match is our free scope checklist. It helps you write down what needs testing before you contact anyone.
How did we build this?
We checked all 192 CISA medical advisory pages on October 9, 2026 (UTC), including each CVE, weakness label, score, vector and credit line. We matched each CVE to CISA's Known Exploited Vulnerabilities catalog (version 2026.10.08, 1,739 entries). The analysis cutoff is October 8, 2026. The core counts come from the two advisory and CVE files. FDA matches, the linked maker table and quoted figures have their own source files.
Where the data came from
- CISA's ICS medical advisory pages: 191 in the medical section, plus one with a medical number that CISA files with its other advisories (ICSMA-18-137-02).
- CISA's Known Exploited Vulnerabilities catalog.
- MITRE's CWE list, version 4.20, for weakness names and groups.
- FDA notices, recall records and guidance for the FDA sections; the original producer of each figure in the source-check table.
- Johnson & Johnson's original Carto 3 PDF for the separate linked-table check.
The rules we used
- One CVE is one vulnerability, however many advisories list it.
- Scores and weakness labels are the ones printed on CISA's pages. Where a CVE has a score in one advisory and only a range in another, we use the score.
- Severity bands follow FIRST's CVSS v3.1 scale.
- "Authentication flaw" means CWE-287 and everything MITRE files under it. The CSV field is
authentication_flaw; it includes certificate and device-identity checks, not just logins. "Hard-coded or default passwords and keys" means CWE-798, CWE-259, CWE-321, CWE-1392 and CWE-1394. - Each advisory gets one maker, vendor or project label and one of ten device groups. Both are our own sorting. The infusion and dispensing group includes medication and supply cabinets.
- "Year" is the year in CISA's advisory number.
- We count CVEs in the vulnerability descriptions, not stray IDs in navigation or unrelated references. In the Contec advisory, the credit paragraph has a typo, CVE-2025-1024. The vulnerability section, update log and researcher's disclosure identify CVE-2025-1204. We count the correct ID once.
- We count each CVE once overall. For a CVE listed more than once, a single published score takes priority over a range-only row. For CVE-2017-0143, this uses Baxter's 8.1 score in every group where that CVE appears. The per-advisory table keeps each page's own scores. All other repeated CVEs have matching values.
- We count outside or anonymous reporting credit together. It is a count of the credit lines, not proof that each reporter is independent or that a penetration test found the flaw.
- Percentages use the denominator printed beside them. They are rounded separately, half up, to one decimal.
- For the FDA recall count, retrieve all records matching
reason_for_recall:cybersecurity, then count distinctres_event_numbervalues. The 60 returned product records form 17 events. - For the Carto 3 check, take the explicit CVE IDs on PDF pages 8–13, remove duplicates, join them to the core CVE IDs, then match that union to the same KEV catalog. The 183 IDs include 21 already counted: 536 + 183 − 21 = 698; 20 / 698 = 2.9%.
How we checked ourselves
- We independently recomputed the submitted data and rechecked all 192 source pages. The 551 CVE listings and 536 distinct IDs matched.
- We compared the inventory with CISA's medical advisory index and official advisory data repository. We used CISA's web pages when the versions disagreed.
- We worked out all 526 populated score-and-vector rows again. All matched. The other 25 listings have only ranges; one repeated CVE has a single score in another advisory, leaving 24 distinct CVEs without a single score.
- Our yearly advisory counts for 2016 to 2024 match the ones MedCrypt published in 2025. MedCrypt counted these advisories before we did.
Where CISA's data files and its web pages disagree, we used the web pages. For example, the repository inventory lacks four advisories, and its ICSMA-21-187-01 file omits CVE-2021-39369, which the page prints. Some scores, vectors and weakness labels also differ. We do not mix in the repository's extra single scores for page rows that give only ranges.
What does this data show, and what does it not show?
It shows what CISA has published about medical device flaws. It does not show how many devices in use are at risk today.
- It counts notices, not danger. A maker that reports its own flaws gets a longer list.
- "Known exploited" is narrow. Here it means a match to CISA's catalog. The 12 matches do not tell us that the other 524 have never been used, or that these attacks took place on medical devices.
- It does not track fixes. A flaw named in 2018 may be long patched, or not.
- Scores rate software, not patient harm.
- Groups and maker names are ours. Sort the file differently and the device and maker tables will shift a little. The totals will not.
- It cannot explain trends. We can see imaging software rise. We cannot see why.
- It is U.S. government data. Flaws reported only to other countries' agencies, or never reported, are not here. CISA's medical category includes hospital software and shared components; it is not a list of FDA-cleared devices or a U.S. device sample.
You can read how The PenTest Index works and how we make money.
How do I cite this page?
Credit The PenTest Index for the counts and the matching, and keep CISA named as the source of the advisories. Keep the date with the number: 536 directly named CVEs and 12 catalog matches use the October 8, 2026 cutoff. Sources were checked October 9, 2026 (UTC).
Copy this citation:
The PenTest Index. "Medical Device Vulnerabilities: 536 CVEs, 12 on CISA's Exploited List." Data as of October 8, 2026; verified October 9, 2026 (UTC). https://thepentestindex.com/research/medical-device-vulnerabilities/
Or copy the finding in one sentence:
CISA's medical advisory pages directly name 536 distinct medical device vulnerabilities in 192 notices since 2016; 12 (2.2%) are on CISA's exploited list, all Microsoft or Apache flaws, according to The PenTest Index's October 2026 analysis of CISA data.
Can I reuse the tables, charts and data?
Yes. You may reuse our original counts, charts and device-group sorting; credit The PenTest Index by name. Keep CISA named as the source of its advisories and catalog; CISA releases the catalog under CC0. MITRE's CWE material and any manufacturer or vendor text keep their own attribution and terms. This permission covers our contribution, not rights in underlying source material.
Where can I download the data?
Every row behind this page is free to download as CSV, and each row carries its source link and check date.
- medical-device-advisories.csv: all 192 advisories, with maker, device group, CVE count, top score, known exploited count, credit and CISA's exploit statement.
- medical-device-cves.csv: all 551 CVE listings (536 different CVEs), with weakness label and group, score, vector and known-exploited status.
- fda-notices-matched-to-cisa.csv: the FDA's 18 notices plus the 2023 Illumina letter, matched to CISA records.
- quoted-numbers-source-check.csv: the repeated numbers, with each original quote and link.
- findings-with-math.csv: main findings, with counts, denominators and the math.
- carto3-referenced-cves.csv: 183 CVE IDs from Johnson & Johnson's linked Carto 3 table, with PDF pages and overlap and KEV checks.
- The four charts as PNG files, each with its source line inside the picture: exploited-list matches, advisories by year, weakness groups, and attack paths.
| Advisory ID | CVE ID | CWE ID | CWE name | Weakness group | CVSS v3 score | Severity | CVSS v3 vector | Score note | Authentication flaw | Hard-coded or default credential | MITRE mapping usage | On CISA KEV | KEV vendor | KEV name | KEV date added | Known ransomware use | Source URL | Check date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ICSMA-17-215-01 | CVE-2008-4250 | CWE-94 | Improper Control of Generation of Code ('Code Injection') | Injection | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Allowed-with-Review | yes | Microsoft | Microsoft Windows Buffer Overflow Vulnerability | 2026-05-20 | Unknown | CISA advisory | 2026-10-09 | |
| ICSMA-17-215-01 | CVE-2017-7269 | CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | Memory Safety | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Discouraged | yes | Microsoft | Microsoft Windows Server Buffer Overflow Vulnerability | 2021-11-03 | Unknown | CISA advisory | 2026-10-09 | |
| ICSMA-17-215-02 | CVE-2015-1635 | CWE-94 | Improper Control of Generation of Code ('Code Injection') | Injection | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Allowed-with-Review | yes | Microsoft | Microsoft HTTP.sys Remote Code Execution Vulnerability | 2022-02-10 | Unknown | CISA advisory | 2026-10-09 | |
| ICSMA-18-058-02 | CVE-2017-0143 | CWE-20 | Improper Input Validation | Improper Input Validation | Score range only on CISA page; no single score | no | no | Discouraged | yes | Microsoft | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | 2021-11-03 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-18-058-02 | CVE-2017-0144 | CWE-20 | Improper Input Validation | Improper Input Validation | Score range only on CISA page; no single score | no | no | Discouraged | yes | Microsoft | Microsoft SMBv1 Remote Code Execution Vulnerability | 2022-02-10 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-18-058-02 | CVE-2017-0145 | CWE-20 | Improper Input Validation | Improper Input Validation | Score range only on CISA page; no single score | no | no | Discouraged | yes | Microsoft | Microsoft SMBv1 Remote Code Execution Vulnerability | 2022-02-10 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-18-058-02 | CVE-2017-0146 | CWE-20 | Improper Input Validation | Improper Input Validation | Score range only on CISA page; no single score | no | no | Discouraged | yes | Microsoft | Microsoft Windows SMB Remote Code Execution Vulnerability | 2022-03-25 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-18-058-02 | CVE-2017-0148 | CWE-20 | Improper Input Validation | Improper Input Validation | Score range only on CISA page; no single score | no | no | Discouraged | yes | Microsoft | Microsoft SMBv1 Server Remote Code Execution Vulnerability | 2022-04-06 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-18-058-02 | CVE-2017-0147 | CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | Sensitive Information Exposure | 5.9 | Medium | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | no | no | Discouraged | yes | Microsoft | Microsoft Windows SMBv1 Information Disclosure Vulnerability | 2022-05-24 | Known | CISA advisory | 2026-10-09 | |
| ICSMA-18-058-02 | CVE-2017-0199 | CWE-264 | Permissions, Privileges, and Access Controls | Category ID only (no group) | Score range only on CISA page; no single score | no | no | Prohibited | yes | Microsoft | Microsoft Office and WordPad Remote Code Execution Vulnerability | 2021-11-03 | Known | CISA advisory | 2026-10-09 | |||
| ICSMA-20-049-01 | CVE-2019-0708 | CWE-20 | Improper Input Validation | Improper Input Validation | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Discouraged | yes | Microsoft | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | 2021-11-03 | Known | CISA advisory | 2026-10-09 | |
| ICSMA-20-170-01 | CVE-2017-0143 | CWE-20 | Improper Input Validation | Improper Input Validation | 8.1 | High | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Discouraged | yes | Microsoft | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | 2021-11-03 | Known | CISA advisory | 2026-10-09 | |
| ICSMA-21-187-01 | CVE-2020-1938 | CWE-20 | Improper Input Validation | Improper Input Validation | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | no | no | Discouraged | yes | Apache | Apache Tomcat Improper Privilege Management Vulnerability | 2022-03-03 | Unknown | CISA advisory | 2026-10-09 |
Source: The CISA advisory source URL and check date appear in each row; KEV fields use the catalog version stated in the data.
Questions people ask
What is a medical device vulnerability?
A medical device vulnerability is a security flaw in a medical device or its software. Someone could use it to break in, steal data, or change how the device works. CISA has named 536 of them in 192 advisories since 2016.
How many medical device vulnerabilities are there?
CISA's medical advisory pages directly name 536 in 192 advisories, from March 29, 2016 to October 8, 2026. Two early advisories also report 1,418 and 460 flaws in outside software without naming each one. Their sum is 1,878, but unknown overlap means we cannot add it to the 536 distinct CVEs.
What is the most common medical device vulnerability?
Access control. Of the 536 vulnerabilities, 210 (39.2%) are access control flaws and 152 (28.4%) are authentication flaws: weak checks of a claimed identity. Forty-two are hard-coded or default passwords and keys.
Does a known vulnerability mean a medical device was hacked?
No. A vulnerability is a flaw that could be used in an attack. Only 12 of the 536 are on CISA's list of flaws used in real attacks, and even that list does not say which devices were hit.
Which medical devices have the most security advisories?
Imaging software has the most: 43 of 192 advisories (22.4%). Infusion pumps, medication and supply systems have 26, and patient monitors have 25. More advisories does not mean more danger.
Is there a medical device vulnerability database?
CISA posts each medical advisory on its website, and the FDA lists 18 cybersecurity safety notices. This page puts all 192 CISA advisories in one free file, with each flaw's score, weakness type and known-exploited status.
What percentage of medical devices are vulnerable?
These sources do not give one current rate for all medical devices. Claroty reported in March 2025 that 9% of the connected medical devices it analyzed carried a known exploited flaw. Always keep the company, the year and the unit with the number.
Where does "6.2 vulnerabilities per medical device" come from?
The earliest source we found is a February 7, 2018 blog post by a security vendor, Sensato. It gives no sample, dates or method. The FBI repeated the figure in 2022, and the GAO repeated the FBI in 2023.
Should a patient stop using a device named in an advisory?
A table cannot decide that. Talk with your care team and follow the maker's current instructions. The FDA says that for the 18 cases it lists, it is not aware of any patient injuries or deaths tied to cybersecurity incidents.
Sources
Sources were checked on October 9, 2026 (UTC). The analysis cutoff is October 8, 2026; the KEV catalog version is 2026.10.08. Historical figures keep the dates of their original reports.
- CISA, ICS advisories and ICS medical advisories (192 advisory pages). https://www.cisa.gov/news-events/ics-advisories
- CISA, Known Exploited Vulnerabilities catalog, version 2026.10.08. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA, how vulnerabilities are added to the catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities
- CISA, advisory data files (cross-check). https://github.com/cisagov/CSAF
- CISA, catalog data and CC0 license. https://github.com/cisagov/kev-data
- Johnson & Johnson, Carto 3 operating-system patch advisory, April 2018. https://www.productsecurity.jnj.com/sites/default/files/2023-10/CARTO3v4-Advisory-040918.pdf
- MITRE, CWE view 1400. https://cwe.mitre.org/data/definitions/1400.html
- FIRST, CVSS v3.1 specification and user guide. https://www.first.org/cvss/v3.1/specification-document
- FDA, Cybersecurity (safety communications table). https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
- FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, February 3, 2026. https://www.fda.gov/media/119933/download
- FDA, Contec and Epsimed patient monitors safety communication, updated July 2, 2025. https://www.fda.gov/medical-devices/safety-communications/cybersecurity-vulnerabilities-certain-patient-monitors-contec-and-epsimed-fda-safety-communication
- FDA, Illumina Universal Copy Service letter, April 27, 2023. https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks
- FDA, device recall data (openFDA), data updated October 8, 2026. https://api.fda.gov/device/recall.json?search=reason_for_recall:cybersecurity&limit=100
- FDA, Medical Device Cybersecurity: What You Need to Know. https://www.fda.gov/consumers/consumer-updates/medical-device-cybersecurity-what-you-need-know
- GAO, GAO-24-106683, December 21, 2023. https://www.gao.gov/assets/gao-24-106683.pdf
- FBI, Private Industry Notification 20220912-001, September 12, 2022. https://www.ic3.gov/CSA/2022/220912.pdf
- Sensato, blog post, February 7, 2018. https://www.sensato.co/post/endless-terrifying-possibilities-call-for-a-good-medical-device-cop
- MedTech Dive, December 1, 2021. https://www.medtechdive.com/news/cybersecurity-medical-devices-hospital-divide-fda/609252/
- Cynerio, press release, January 19, 2022 (archived copy). https://web.archive.org/web/20220527214113/https://www.cynerio.com/blog/cynerio-research-finds-critical-medical-device-risks-continue-to-threaten-hospital-security-and-patient-safety
- Unit 42, Palo Alto Networks, March 2, 2022. https://unit42.paloaltonetworks.com/infusion-pump-vulnerabilities/
- Claroty, press release, March 26, 2025. https://claroty.com/press-releases/new-research-from-clarotys-team82-highlights-riskiest-medical-device-exposures-in-healthcare-environments
- Claroty, State of CPS Security: Healthcare Exposures 2025. https://web-assets.claroty.com/resource-downloads/state-of-cps-security-healthcare-2025.pdf
- Health-ISAC, Finite State and Securin, 2023 State of Cybersecurity for Medical Devices and Healthcare Systems. https://health-isac.org/wp-content/uploads/11883-StateMedSecurityReport_v6.pdf
- MedCrypt, ICS-CERT medical device advisory trends, April 2, 2025. https://www.medcrypt.com/cybersecurity-whitepapers/whitepapers-ics-cert-2024-medical-device-cybersecurity-trends
- Menon, Frontiers in Digital Health, March 2026. https://www.frontiersin.org/journals/digital-health/articles/10.3389/fdgth.2026.1701551/full
- FDA, Cybersecurity in Medical Devices Frequently Asked Questions. https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs
- Baxter, acquisition of Hillrom completed December 13, 2021; company release filed with the SEC. https://www.sec.gov/Archives/edgar/data/10456/000162828021024946/bax-20211213pressreleasexe.htm
- FDA, URGENT/11 press release, October 1, 2019. https://www.fda.gov/news-events/press-announcements/fda-informs-patients-providers-and-manufacturers-about-potential-cybersecurity-vulnerabilities
- MITRE, CWE version 4.20 data. https://cwe.mitre.org/data/xml/cwec_v4.20.xml.zip
The PenTest Index Research is the research and reference section of thepentestindex.com.