by
Gus Iversen, Editor in Chief | May 13, 2026
Revolution Apex CT system
GE HealthCare is recalling 24 Revolution Apex CT systems in the U.S. due to a cybersecurity vulnerability tied to AW Server deployments through Edison Health Link-based CT Smart Subscription configurations
The recall, classified as Class 2, affects Revolution Apex systems with model number 5590000-20. The Waukesha, Wisconsin-based imaging OEM initiated the action March 26. The FDA identified the root cause as a software design issue.
According to
the notice, the vulnerability affects AW Server authentication when deployed via Edison Health Link in conjunction with certain Revolution Apex, Revolution Ascend and Revolution CT systems. The affected devices fall under product code JAK for CT X-ray systems.

Ad Statistics
Times Displayed: 344099
Times Visited: 21052 MIT labs, experts in Multi-Vendor component level repair of: MRI Coils, RF amplifiers, Gradient Amplifiers Contrast Media Injectors. System repairs, sub-assembly repairs, component level repairs, refurbish/calibrate. info@mitlabsusa.com/+1 (305) 470-8013
GE HealthCare said customers may continue using the systems while corrective actions are implemented, provided facilities follow existing cybersecurity and imaging guidance outlined in the user manuals.
“Patient safety and security are our top priority," a GE HealthCare spokesperson told HCB News. "We have a comprehensive product security program and work with customers to implement best practices and reduce risk. We are notifying customers about this issue, providing instructions allowing them to continue using their devices, and are in the process of implementing a correction. There have been no injuries or unauthorized access to patient data reported to GE HealthCare as a result of this issue."
The company instructed users not to rely solely on 3D or slab reconstructions for diagnostic measurements. “Always check measurement points position and refer to 2D baseline views (acquisition images or reformatted images of minimal thickness) to confirm measurements,” the notice stated.
As an interim step, GE HealthCare plans to deactivate AW Server authentication through the CT system on affected Edison Health Link-based Smart Subscription configurations. The company said alternative authentication methods, including direct application launch from the CT console and LDAP-based hospital directory integration, will remain available.
GE HealthCare plans to deploy a software update to affected systems at no cost to customers.
The recall applies to 24 units distributed nationwide in the U.S. Serial numbers listed in the FDA report include systems manufactured between 2020 and 2023.
Customers were instructed to notify all potential users within their facilities and return an acknowledgment form to GE HealthCare.
Back to HCB News