ZeroHour
CISA Advisoriespublished ()ingested CISA

Orthanc DICOM Server

mediumAdvisoryimportance 25CVE-2026-87020
AI summary · glm-5.3-flash

CISA advisory flags CVE-2026-87020, an integer overflow in Orthanc DICOM Server <1.13.0 causing heap out-of-bounds write and denial of service when decoding crafted PNG/JPEG images.

CISA published ICSMA-26-253-02 for Orthanc DICOM Server versions below 1.13.0, used in healthcare environments worldwide. CVE-2026-87020 (CWE-190) is an integer overflow in pitch and buffer-size computation causing a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can crash the Orthanc process and cause denial of service; CVSS v3.1 is 8.1 HIGH. CISA states no known public exploitation targeting this flaw has been reported.

  • CVE-2026-87020 affects Orthanc DICOM Server <1.13.0 with CVSS 3.1 score 8.1.
  • Authenticated remote attackers can crash the process via crafted PNG or JPEG images.
  • Healthcare and Public Health is the affected critical infrastructure sector; deployment is worldwide.
  • CISA recommends minimizing network exposure and updating beyond version 1.13.0.
OrganizationsCISA

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87020
Heap Out-of-Bounds Write in Orthanc DICOM Server PNG Decoding

CVE-2026-87020 is an integer overflow (CWE-190) in the pitch and buffer-size computation used when Orthanc DICOM Server decodes PNG images, which causes a heap out-of-bounds write. It is triggered when the server decodes an attacker-supplied PNG; the CVSS 4.0 vector (AV:N/AC:L/PR:L/UI:N) indicates the attacker needs network access and some level of authenticated privileges, with no user interaction required. A successful out-of-bounds write corrupts heap memory, which per the scoring has high integrity and availability impact (service crashes and data corruption); arbitrary code execution has not been demonstrated publicly. Affected parties are operators of Orthanc DICOM servers, which are commonly used for medical imaging in hospitals, clinics, and research environments; the data does not specify affected or fixed version ranges. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

Do: No fixed version number was provided in the data; monitor the Orthanc project's official security advisory and upgrade to the patched release as soon as it is published. In the meantime, restrict Orthanc's REST/HTTP (default 8042) and DICOM (default 4242) services to trusted, authenticated users and internal networks, review which clients can submit image data for decoding, and investigate any unexplained service crashes.

7.2
  • Orthanc (open-source project; assigned by CISA ICS-CERT) Orthanc DICOM Server
moderate≈10k–100k installations worldwide (estimate; mostly internal hospital/research deployments, with only a subset internet-exposed)
Full article493 words · extracted from cisa.gov · click to collapse

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.

The following versions of Orthanc DICOM Server are affected:

  • Orthanc DICOM Server <1.13.0. (CVE-2026-87020)
CVSS Vendor Equipment Vulnerabilities
v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or Wraparound

Background

  • Critical Infrastructure Sectors: Healthcare and Public Health
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Belgium

Vulnerabilities

Expand All +

CVE-2026-87020

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.

View CVE Details


Affected Products

Orthanc DICOM Server

Vendor:
Orthanc

Product Version:
Orthanc Orthanc DICOM Server: <1.13.0.

Product Status:
known_affected

Relevant CWE: CWE-190 Integer Overflow or Wraparound


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
4.0 7.2 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments

  • Andrej Tomci reported this vulnerability to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

Locate control system networks and remote devices behind firewalls and isolating them from business networks.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

Do not click web links or open attachments in unsolicited email messages.

Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.

Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-10
Date Revision Summary
2026-09-10 1 Initial Publication

Legal Notice and Terms of Use

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02