Orthanc DICOM Server
A vulnerability (CVE-2026-87020) exists in Orthanc DICOM Server versions prior to 1.13.0, allowing a remote, authenticated attacker to cause a denial-of-service by providing a specially crafted PNG or JPEG image. This could impact critical infrastructure sectors like healthcare and public health globally.
A vulnerability (CVE-2026-87020) exists in Orthanc DICOM Server versions prior to 1.13.0, allowing a remote, authenticated attacker to cause a denial-of-service by providing a specially crafted PNG or JPEG image. This stems from an integer overflow in a specified pitch and buffer-size computation, leading to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG. The vulnerability is deployed worldwide and affects organizations with Orthanc DICOM Server or Orthanc installed. The vulnerability is currently not being actively exploited publicly. CISA recommends users update to version 1.13.0. To mitigate the risk, CISA advises minimizing network exposure for control system devices, isolating them behind firewalls, and utilizing secure remote access methods like VPNs, recognizing that VPNs themselves can have vulnerabilities. Organizations are encouraged to perform impact analysis and risk assessments and to implement proactive cybersecurity strategies for industrial control systems assets.