The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning that vulnerabilities in Vertikal Systems' hospital information management software could allow unauthorized access to sensitive patient data. The affected software, primarily used by smaller hospitals and clinics outside the United States, contains flaws in its Hospital Manager Backend Services that can be remotely exploited with low attack complexity. One of the vulnerabilities involves the exposure of the ASP.NET tracing endpoint (trace.axd) without authentication, potentially leaking live request traces, session identifiers, authorization headers, and internal server information.
CISA emphasized that successful exploitation of these vulnerabilities could enable attackers to obtain and disclose confidential information, posing significant risks to healthcare organizations relying on Vertikal Systems products. The agency recommends that affected entities review the advisory and implement mitigation measures to protect patient data and prevent unauthorized access. The vulnerabilities highlight ongoing challenges in securing healthcare IT infrastructure, especially for smaller providers using third-party management solutions.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
CISA warned that CVE-2025-54459 and CVE-2025-61959 could allow unauthorized remote access to sensitive patient and system data in Vertikal Systems' Hospital Manager Backend Services. The agency said customers should apply fixes and reduce internet exposure through segmentation, firewalls, and secured remote access.
Vertikal Systems remediated two remotely exploitable flaws in Hospital Manager Backend Services affecting versions released before Sept. 19, 2025. The issues involved an exposed unauthenticated ASP.NET tracing endpoint and verbose ASP.NET error pages that could leak sensitive patient and system information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.