Cybersecurity concept

Customer Security Newsletter - November 2025

Welcome to the October 2025 MEDITECH Customer Security Newsletter, where we provide you with information and resources to give you insight on security challenges facing your organization and the healthcare community as a whole. Here we endeavor to provide some good information to help you improve your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.


Known Exploited Vulnerabilities

From October 8, 2025 until the writing of this bulletin, there have been 24 known exploited vulnerabilities added to CISA's list. They are CVE-2021-43798, CVE-2025-47827, CVE-2025-24990, CVE-2025-59230, CVE-2016-7836, CVE-2025-54253, CVE-2022-48503, CVE-2025-2746, CVE-2025-2747, CVE-2025-33073, CVE-2025-61884, CVE-2025-61932, CVE-2025-54236, CVE-2025-59287, CVE-2025-6204, CVE-2025-6205, CVE-2025-41244, CVE-2025-24893, CVE-2025-48703, CVE-2025-11371, CVE-2025-21042, CVE-2025-12480, CVE-2025-62215, and CVE-2025-9242.

All of these additions are based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks. When looking at the catalog, the CVEs are listed from most recently added by default and the list may be manipulated by using the provided filters. This list was most recently reviewed on November 14, 2025.


Vulnerabilities for Hospitals to Watch Out For

These significant vulnerabilities have been shown to have been weaponized in August and September 2025. Intelligence indicates a high degree of caution for hospital infrastructures.

  • CVE-2025-59287 (CRITICAL): Microsoft Windows Server Update Services (WSUS) Remote Code Execution
  • CVE-2025-62215 (HIGH): Microsoft Windows Kernel Elevation of Privilege
  • CVE-2025-24990 (HIGH): Windows Agere Modem Driver Elevation of Privilege
  • CVE-2025-59230 (HIGH): Windows Remote Access Connection Manager Elevation of Privilege
  • CVE-2025-12480 (CRITICAL): Gladinet Triofox/CentreStack Improper Access Control
  • CVE-2025-9242 (CRITICAL): WatchGuard Firebox Out-of-Bounds Write

News

CISA, FBI and Partners Unveil Critical Guidance to Protect Against Akira Ransomware Threat

This CISA and FBI joint advisory provides updated tactics, techniques, and procedures (TTPs) and critical mitigation steps to help organizations, including those in manufacturing, healthcare, and education, defend against the evolving Akira ransomware threat. Read more here... 

US Congress Moves to Revive CISA 2015 After Shutdown

On November 12, 2025, H-ISAC linked an article reporting that Congress is moving to temporarily revive the Cybersecurity Information Sharing Act (CISA) of 2015 through January 30, 2026, in the wake of a government shutdown that caused the critical law to expire, eliminating the legal protections (like liability shields and antitrust exemptions) necessary for companies to share cyberthreat intelligence with federal agencies. Read more here...


Additional Resources


Talk to us!

We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?

We also have a question for you that is important to us. What are your largest concerns or security hopes for 2025?

Please let us know by contacting us!

Until next time, stay alert out there!