Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · medtronic

medtronic

· 2 Critical

Total CVEs

29

Critical

2

Products

200

Search All CVEs →

29

Products (200)

carelink network4 CVEsvalleylab ft10 energy platform firmware4 CVEsvalleylab ft10 energy platform4 CVEsmycarelink smart model 25000 firmware3 CVEsmycarelink smart model 250003 CVEs2090 carelink programmer3 CVEs2090 carelink programmer firmware3 CVEsamplia crt-d firmware2 CVEscarelink 20902 CVEsmycarelink 24950 patient monitor2 CVEsmycarelink 24950 patient monitor firmware2 CVEsmycarelink 24952 patient monitor2 CVEsmycarelink 24952 patient monitor firmware2 CVEsclaria crt-d2 CVEsclaria crt-d firmware2 CVEscompia crt-d2 CVEscompia crt-d firmware2 CVEsconcerto crt-d2 CVEsconcerto crt-d firmware2 CVEsn\'vision 88402 CVEsn\'vision 8840 firmware2 CVEsn\'vision 88702 CVEsn\'vision 8870 firmware2 CVEsnayamed nd icd2 CVEsnayamed nd icd firmware2 CVEsconcerto ii crt-d2 CVEsprimo icd2 CVEsprimo icd firmware2 CVEsconcerto ii crt-d firmware2 CVEsconsulta crt-d2 CVEsconsulta crt-d firmware2 CVEsevera icd2 CVEsevera icd firmware2 CVEsmirro icd2 CVEssecura icd2 CVEssecura icd firmware2 CVEsvalleylab exchange client2 CVEsvalleylab fx8 energy platform2 CVEsvalleylab fx8 energy platform firmware2 CVEsvalleylab ls10 energy platform2 CVEsvalleylab ls10 energy platform firmware2 CVEsvirtuoso icd2 CVEsvirtuoso icd firmware2 CVEsvirtuoso ii icd2 CVEsvirtuoso ii icd firmware2 CVEsvisia af icd2 CVEsvisia af icd firmware2 CVEsviva crt-d2 CVEsmirro icd firmware2 CVEsviva crt-d firmware2 CVEscarelink 2090 firmware2 CVEs24950 mycarelink monitor firmware2 CVEs24952 mycarelink monitor2 CVEs24952 mycarelink monitor firmware2 CVEs24950 mycarelink monitor2 CVEsamplia crt-d2 CVEsminimed 670g mmt-1741 firmware1 CVEsminimed 670g mmt-17421 CVEsminimed 670g mmt-1742 firmware1 CVEsminimed 670g mmt-17601 CVEsminimed 670g mmt-1760 firmware1 CVEsminimed 670g mmt-17611 CVEsminimed 670g mmt-1761 firmware1 CVEsminimed 670g mmt-17621 CVEsminimed 670g mmt-1762 firmware1 CVEsminimed 670g mmt-17801 CVEsminimed 670g mmt-1780 firmware1 CVEsminimed 670g mmt-17811 CVEsminimed 670g mmt-1781 firmware1 CVEsminimed 670g mmt-17821 CVEsminimed 670g mmt-1782 firmware1 CVEsminimed paradigm 508 insulin pump1 CVEsminimed paradigm 508 insulin pump firmware1 CVEsminimed paradigm 5111 CVEsminimed paradigm 511 firmware1 CVEsminimed paradigm 5121 CVEsminimed paradigm 512 firmware1 CVEsminimed paradigm 5151 CVEsminimed paradigm 515 firmware1 CVEsminimed paradigm 5221 CVEsminimed paradigm 522 firmware1 CVEsminimed paradigm 522k1 CVEsminimed paradigm 522k firmware1 CVEsminimed paradigm 5231 CVEsminimed paradigm 523 firmware1 CVEsminimed paradigm 523k1 CVEsminimed paradigm 523k firmware1 CVEsminimed paradigm 7121 CVEsminimed paradigm 712 firmware1 CVEsminimed paradigm 712e1 CVEsminimed paradigm 712e firmware1 CVEsminimed paradigm 7151 CVEsminimed paradigm 715 firmware1 CVEsminimed paradigm 7221 CVEsminimed paradigm 722 firmware1 CVEsminimed paradigm 722k1 CVEsminimed paradigm 722k firmware1 CVEsminimed paradigm 7231 CVEsminimed paradigm 723 firmware1 CVEsminimed paradigm 723k1 CVEsminimed paradigm 723k firmware1 CVEsminimed paradigm real-time mmt-5221 CVEsminimed paradigm real-time mmt-522 firmware1 CVEsminimed paradigm real-time mmt-7221 CVEsminimed paradigm real-time mmt-722 firmware1 CVEsminimed paradigm revel mmt-5231 CVEsminimed paradigm revel mmt-523 firmware1 CVEsminimed paradigm revel mmt-523k1 CVEsminimed paradigm revel mmt-523k firmware1 CVEsminimed paradigm revel mmt-7231 CVEsminimed paradigm revel mmt-723 firmware1 CVEsminimed paradigm revel mmt-723k1 CVEsminimed paradigm revel mmt-723k firmware1 CVEsminimed paradigm veo 5541 CVEsminimed paradigm veo 554 firmware1 CVEsminimed paradigm veo 554cm1 CVEsminimed paradigm veo 554cm firmware1 CVEsminimed paradigm veo 7541 CVEsminimed paradigm veo 754 firmware1 CVEsminimed paradigm veo 754cm1 CVEsminimed paradigm veo 754cm firmware1 CVEsmmt-11511 CVEsmmt-1151 firmware1 CVEsmmt-11521 CVEsmmt-1152 firmware1 CVEsmmt-13511 CVEsmmt-1351 firmware1 CVEsmmt-13521 CVEsmmt-1352 firmware1 CVEsmmt-73061 CVEsmmt-7306 firmware1 CVEsmycarelink monitor1 CVEsmycarelink monitor 249501 CVEsmycarelink monitor 24950 firmware1 CVEsmycarelink monitor 249521 CVEsmycarelink monitor 24952 firmware1 CVEsmycarelink monitor firmware1 CVEspaceart optima1 CVEsprotecta crt-d1 CVEsprotecta crt-d firmware1 CVEsprotecta icd1 CVEsprotecta icd and crt-d1 CVEsprotecta icd and crt-d firmware1 CVEsprotecta icd firmware1 CVEsparadigm wireless insulin pump1 CVEs29901 encore programmer1 CVEs29901 encore programmer firmware1 CVEscarelink 2090 programmer1 CVEscarelink 2090 programmer firmware1 CVEscarelink 9790 programmer1 CVEscarelink 9790 programmer firmware1 CVEscarelink monitor1 CVEscarelink monitor 2490c1 CVEscarelink monitor 2490c firmware1 CVEscarelink monitor firmware1 CVEsguardian link 2 transmitter mmt-77301 CVEsguardian link 2 transmitter mmt-7730 firmware1 CVEsguardian link 2 transmitter mmt-77311 CVEsguardian link 2 transmitter mmt-7731 firmware1 CVEsguardian link 2 transmitter mmt-77381 CVEsguardian link 2 transmitter mmt-7738 firmware1 CVEsguardian link 2 transmitter mmt-77751 CVEsguardian link 2 transmitter mmt-7775 firmware1 CVEsguardian link 3 transmitter mmt-78101 CVEsguardian link 3 transmitter mmt-7810 firmware1 CVEsguardian link 3 transmitter mmt-78111 CVEsguardian link 3 transmitter mmt-7811 firmware1 CVEsinterstim x clinician1 CVEsmaximo ii crt-d1 CVEsmaximo ii crt-d and lcd1 CVEsmaximo ii crt-d and lcd firmware1 CVEsmaximo ii crt-d firmware1 CVEsmaximo ii icd1 CVEsmaximo ii icd firmware1 CVEsmicro clinician1 CVEsminimed 5081 CVEsminimed 508 firmware1 CVEsminimed 530g mmt-5511 CVEsminimed 530g mmt-551 firmware1 CVEsminimed 530g mmt-7511 CVEsminimed 530g mmt-751 firmware1 CVEsminimed 620g mmt-17501 CVEsminimed 620g mmt-1750 firmware1 CVEsminimed 630g mmt-17151 CVEsminimed 630g mmt-1715 firmware1 CVEsminimed 630g mmt-17541 CVEsminimed 630g mmt-1754 firmware1 CVEsminimed 630g mmt-17551 CVEsminimed 630g mmt-1755 firmware1 CVEsminimed 640g mmt-17111 CVEsminimed 640g mmt-1711 firmware1 CVEsminimed 640g mmt-17121 CVEsminimed 640g mmt-1712 firmware1 CVEsminimed 640g mmt-17511 CVEsminimed 640g mmt-1751 firmware1 CVEsminimed 640g mmt-17521 CVEsminimed 640g mmt-1752 firmware1 CVEsminimed 670g mmt-17401 CVEsminimed 670g mmt-1740 firmware1 CVEsminimed 670g mmt-17411 CVEs

Recent Vulnerabilities

View all 29
CVE-2025-12997LOW 2.2

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.

CVE-2025-12996MEDIUM 4.1

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

CVE-2025-12995HIGH 8.1

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

CVE-2025-12994MEDIUM 5.3

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.

CVE-2023-31222CRITICAL 9.8

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity.

CVE-2023-25931MEDIUM 6.4

Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy application, which has greater control over therapy parameters than the patient app. Changes still cannot be made outside of the established therapy parameters of the programmer. For unauthorized access to occur, an individual would need physical access to the Smart Programmer.

CVE-2022-32537MEDIUM 4.8

A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

CVE-2020-27252HIGH 8.8

Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.

CVE-2020-25187HIGH 8.8

Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software stack. The heap overflow could allow an attacker to remotely execute code on the MCL Smart Patient Reader, potentially leading to control of the device

CVE-2020-25183HIGH 8.0

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.

CVE-2019-13543MEDIUM 5.8

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.

CVE-2019-13539HIGH 7.0

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.

CVE-2019-13535MEDIUM 4.6

In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.

CVE-2019-13531MEDIUM 4.8

In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism used for authentication between the FT10/LS10 Energy Platform and instruments can be bypassed, allowing for inauthentic instruments to connect to the generator.

CVE-2019-10964HIGH 7.1

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

CVE-2019-6540MEDIUM 6.5

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.

CVE-2019-6538CRITICAL 9.3

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement authentication or authorization. An attacker with adjacent short-range access to an affected product, in situations where the product’s radio is turned on, can inject, replay, modify, and/or intercept data within the telemetry communication. This communication protocol provides the ability to read and write memory values to affected implanted cardiac devices; therefore, an attacker could exploit this communication protocol to change memory in the implanted cardiac device.

CVE-2018-18984MEDIUM 4.6

Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .

CVE-2018-10634MEDIUM 4.8

Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.

CVE-2018-10626MEDIUM 4.4

Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

CVE-2018-10622MEDIUM 6.8

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

CVE-2018-10631MEDIUM 6.3

The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.

CVE-2018-8870MEDIUM 6.4

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.

CVE-2018-8868MEDIUM 6.2

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can exploit other vulnerabilities to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.

CVE-2018-10596HIGH 7.1

Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initially establish an encapsulated IP-based VPN connection to a Medtronic-hosted update network. Once the VPN is established, it makes a request to a HTTP (non-TLS) server across the VPN for updates, which responds and provides any available updates. The programmer-side (client) service responsible for this HTTP request does not check to ensure it is still connected to the VPN before making the HTTP request. Thus, an attacker could cause the VPN connection to terminate (through various methods and attack points) and intercept the HTTP request, responding with malicious updates via a man-in-the-middle attack. The affected products do not verify the origin or integrity of these updates, as it insufficiently relied on the security of the VPN. An attacker with remote network access to the programmer could influence these communications.