CERT-FR and CERT Santé have warned that recurring critical vulnerabilities in software deployed by French healthcare organizations threaten medical-data confidentiality, continuity of care and patient safety. Their joint report documents anonymized cases involving exposed secrets, administrator credentials embedded in application code, SQL injection, cross-site scripting, unauthenticated internet-facing services and broken access controls. The report highlights active exploitation of authorization flaws in healthcare SaaS platforms after attackers compromise professional accounts through phishing or credential stuffing, enabling access to other users’ or organizations’ data. Widespread use of affected products creates the potential for attacks against many healthcare providers simultaneously.
Vendor remediation remains a major obstacle: an Agence du numérique en santé survey found that 74% of respondents had encountered vendors that delayed or refused fixes. Vulnerability handling exceeded a year at four major vendors, and final patch deployment for one medium-severity flaw was scheduled five years after disclosure. Despite improving vendor engagement and transparency, the CERTs consider observed security practices inadequate and recommend robust authentication and least-privilege access, rather than weakening protections to accommodate customer requests. Healthcare organizations should review internet exposure and vendor remediation commitments. The report also highlights Cyber Resilience Act vulnerability-reporting requirements applicable since September 11, 2026, ahead of full application in December 2027, with potential penalties reaching €15 million or 2.5% of worldwide annual turnover.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CERT Santé handled 400 malicious incidents during 2025, approximately 22% more than in 2024.
CERT Santé handled 328 malicious incidents during 2024, establishing the baseline for the subsequent increase in its annual incident workload.
CERT Santé and CERT-FR published report CERTFR-2026-CTI-007 using anonymized real-world cases to expose recurring healthcare software vulnerabilities and remediation failures. They urged vendors and healthcare organizations to implement robust authentication and least-privilege access, warning of risks to health-data confidentiality, continuity of care, and patient safety.
The report describes particularly active exploitation of authorization vulnerabilities in healthcare SaaS solutions. Attackers compromised professional accounts through phishing or credential stuffing, then used authorization flaws to expand access to data.
CERT Santé and CERT-FR identified readily internet-exploitable vulnerabilities in multiple healthcare solutions, including exposed secrets and administrator credentials, SQL injection, cross-site scripting, and unauthenticated services. Broken access controls also allowed account holders to access other users’ or healthcare establishments’ data.
An Agence du numérique en santé survey found that 74% of respondents had encountered vendors that delayed or refused vulnerability fixes. It also found that 82% of healthcare establishments had become aware of vulnerabilities during the preceding 12 months and 90% lacked a formal vulnerability-reporting channel to vendors.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcecyberveille.ch
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.