Customer Security Newsletter - February 2026

Welcome to the February 2026 MEDITECH Customer Security Newsletter, where we provide you with information and resources to give you insight on security challenges facing your organization and the healthcare community as a whole. Here we endeavor to provide some good information to help you improve your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.


Known Exploited Vulnerabilities

From January 6, 2026, until the writing of this bulletin, there have been 29 known exploited vulnerabilities added to CISA's list. They are CVE-2025-11953, CVE-2026-24423, CVE-2026-21513, CVE-2026-21525, CVE-2026-21510, CVE-2026-21533, CVE-2026-21519, CVE-2026-21514, CVE-2021-39935, CVE-2025-64328, CVE-2019-19006, CVE-2025-40551CVE-2026-1281CVE-2026-24858CVE-2026-21509CVE-2026-24061CVE-2026-23760CVE-2025-52691CVE-2018-14634CVE-2024-37079CVE-2025-54313CVE-2025-31125CVE-2025-34026CVE-2025-68645CVE-2026-20045CVE-2026-20805CVE-2025-8110CVE-2025-37164, and CVE-2009-0556.

All of these additions are based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks. When looking at the catalog, the CVEs are listed from most recently added by default and the list may be manipulated by using the provided filters. This list was most recently reviewed on February 11, 2026.


Vulnerabilities for Hospitals to Watch Out For

These significant vulnerabilities have been shown to have been weaponized in December 2025 and January 2026. Intelligence indicates a high degree of caution for healthcare infrastructures.


News

Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS)

Discover how a premier national security program is paving a high-stakes career path for the next generation of cyber defenders by offering full scholarships in exchange for a mission to protect the country's most critical infrastructure. 

Access broker pleads guilty to helping target 50 companies

On February 3, 2026, H-ISAC linked an article about a single prolific hacker who breached over 50 global organizations, fueling a massive wave of ransomware attacks before federal investigators finally untangled his web of digital destruction. 


Additional Resources


Talk to us!

We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?

We also have a question for you that is important to us. What are your largest concerns or security hopes for 2026?

Please let us know by contacting us!

Until next time, stay alert out there!