Hack Attack: Hospital Manager Backend Services Vulnerability Exposes Sensitive Data

Attention all healthcare cyberspace defenders: Before September 19, 2025, Vertikal Systems’ Hospital Manager Backend Services was about as secure as a screen door on a submarine. View CSAF for more details on how unauthorized users could access sensitive information and how to stay protected.

Pro Dashboard

Hot Take:

In a shocking revelation, Vertikal Systems’ Hospital Manager Backend Services was found to be more open than a 24/7 convenience store, serving up sensitive information to any cyber hooligan who knew where to look. But fret not, dear healthcare warriors! The vulnerabilities have been patched, and your sensitive data is now safer than a cat in a tree. Just remember, the only thing that should be exposed in a hospital is the patient file, not the backend.

Key Points:

– Hospital Manager Backend Services had vulnerabilities allowing unauthorized access to sensitive data.
– CVE-2025-54459 and CVE-2025-61959 were the culprits, scoring 8.7 and 6.9 on the CVSS v4 scale respectively.
– The vulnerabilities were exploitable remotely with low attack complexity.
– Vertikal Systems fixed the issues by September 19, 2025.
– No known public exploitation of these vulnerabilities has been reported.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?