Health software makers sit on bugs for years, France warns

Published

One flaw in a piece of health software was reported to its maker, rated medium severity, and given a fix whose deployment was scheduled for five years later. That case sits in a report published on October 2 by CERT-FR, the national response team run by France's cybersecurity agency ANSSI, and CERT Santé, the French health sector's response team. Their conclusion is blunt: the companies behind much of France's health software are still not handling security flaws fast enough for the threat their customers face.

The report, CERTFR-2026-CTI-007 (full PDF, in French), draws on anonymised real cases the two teams handled while coordinating fixes for vulnerabilities reported by third parties and while responding to incidents. It names no vendor, by design.

More than a year to fix, at four major vendors

At four significant health software vendors, vulnerability cases still open have been running for more than a year. The CERTs blame familiar habits: security fixes shipped only inside feature releases, which customers delay or skip because they cost money or change workflows; so many supported versions that every patch must be tested over and over; no channel for telling customers a fix exists; old code bases that need costly rework; and, for some products, medical device certification rules.

A recent survey of health establishments by France's digital health agency, cited in the report, points the same way: 82% of respondents learned of vulnerabilities in their systems in the past twelve months, 74% faced vendors who were slow to fix vulnerabilities or refused to, and 90% have no formal channel for reporting them. Malicious incidents handled by CERT Santé rose from 328 in 2024 to 400 in 2025, up 22%.

Passwords a browser could fetch

Products from at least three major vendors mishandled secrets. In one, a server password could be retrieved simply by typing a URL into a browser. Others exposed a .git directory containing source code with secrets in it, embedded the administrator login in the application code, or left remote maintenance credentials at their defaults across several sites. In one case, credentials in the code plus server access granted at dozens of health establishments could have exposed thousands of patients' data. Those flaws have since been fixed.

The teams also found many internet-exposed instances of one health product reachable without authentication. The vendor asked customers to close the VNC remote access; some did, while others kept it and signed a liability waiver.

Logged-in users reading other patients' files

The weakness the CERTs say is being actively exploited now, especially in SaaS health platforms, is broken access control. Attackers compromise a health professional's account through phishing or stolen passwords, then abuse weak permission checks to read data belonging to other users or establishments, harvesting health data at scale while staying hard to spot. Some of that over-broad access was built deliberately, at customers' request, to ease collaboration. One counter-audit also found an application still open to several cross-site scripting flaws more than a year after its first fix.

Ship security fixes on their own

The report tells vendors to release security fixes separately from feature updates, use proven security components instead of home-grown ones, enforce least privilege, and give remote access tools strong native authentication. A web application firewall, sometimes sold by the vendor itself, is no substitute for fixing the code. It also reminds them that the EU Cyber Resilience Act applies fully from December 11, 2027, that its duty to report actively exploited vulnerabilities has applied since September 11, 2026, and that France's market regulator for the law, ANFR, can impose fines of up to 15 million euros or 2.5% of global turnover. The CERTs say they may report vendor failings to it.

CERT-FR has recently flagged other easily exploited exposures, including mass Metabase break-ins, and the France profile tracks the wider picture. What stands out here is how ordinary the holes are: default passwords, open remote desktops and missing permission checks, left in place because fixing them was nobody's priority.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions