Spacelabs Healthcare Sentinel versions 10.5.x and later, and 11.x.x before 11.6.0, are affected by **CVE-2026-0611, an unauthenticated remote code execution flaw tied to a deprecated **.NET Remoting HTTP** channel. The vulnerable service listens on port 8989` and can expose arbitrary file read and write functionality when attackers supply valid .NET URI endpoints, creating a path to compromise the application without authentication.
Researchers reported that attackers could use the file-write access to place ASPX webshells in the IIS wwwroot directory and execute code on the target system. Advisories note that port 8989 is not exposed by default in Sentinel deployments, meaning exploitation depends on the remoting service having been deliberately made network-accessible through configuration or network policy changes. The issue was credited to Victor A. Morales and Jan A. Rodriguez of GM Sectec, Corp.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The vulnerability record for CVE-2026-0611 was received by disclosure@vulncheck.com. The flaw affects Spacelabs Healthcare Sentinel and enables unauthenticated remote code execution when the .NET Remoting HTTP channel on port 8989 is exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.