Orthanc DICOM Server
CISA advisory flags CVE-2026-87020, an integer overflow in Orthanc DICOM Server <1.13.0 causing heap out-of-bounds write and denial of service when decoding crafted PNG/JPEG images.
CISA published ICSMA-26-253-02 for Orthanc DICOM Server versions below 1.13.0, used in healthcare environments worldwide. CVE-2026-87020 (CWE-190) is an integer overflow in pitch and buffer-size computation causing a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can crash the Orthanc process and cause denial of service; CVSS v3.1 is 8.1 HIGH. CISA states no known public exploitation targeting this flaw has been reported.
- CVE-2026-87020 affects Orthanc DICOM Server <1.13.0 with CVSS 3.1 score 8.1.
- Authenticated remote attackers can crash the process via crafted PNG or JPEG images.
- Healthcare and Public Health is the affected critical infrastructure sector; deployment is worldwide.
- CISA recommends minimizing network exposure and updating beyond version 1.13.0.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87020 | Heap Out-of-Bounds Write in Orthanc DICOM Server PNG Decoding CVE-2026-87020 is an integer overflow (CWE-190) in the pitch and buffer-size computation used when Orthanc DICOM Server decodes PNG images, which causes a heap out-of-bounds write. It is triggered when the server decodes an attacker-supplied PNG; the CVSS 4.0 vector (AV:N/AC:L/PR:L/UI:N) indicates the attacker needs network access and some level of authenticated privileges, with no user interaction required. A successful out-of-bounds write corrupts heap memory, which per the scoring has high integrity and availability impact (service crashes and data corruption); arbitrary code execution has not been demonstrated publicly. Affected parties are operators of Orthanc DICOM servers, which are commonly used for medical imaging in hospitals, clinics, and research environments; the data does not specify affected or fixed version ranges. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported. Do: No fixed version number was provided in the data; monitor the Orthanc project's official security advisory and upgrade to the patched release as soon as it is published. In the meantime, restrict Orthanc's REST/HTTP (default 8042) and DICOM (default 4242) services to trusted, authenticated users and internal networks, review which clients can submit image data for decoding, and investigate any unexplained service crashes. | 7.2 | — |
| moderate≈10k–100k installations worldwide (estimate; mostly internal hospital/research deployments, with only a subset internet-exposed) |
Full article493 words · extracted from cisa.gov · click to collapse
Summary
Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.
The following versions of Orthanc DICOM Server are affected:
- Orthanc DICOM Server <1.13.0. (CVE-2026-87020)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 8.1 | Orthanc | Orthanc DICOM Server | Integer Overflow or Wraparound |
Background
- Critical Infrastructure Sectors: Healthcare and Public Health
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Belgium
Vulnerabilities
CVE-2026-87020
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.
Affected Products
Orthanc DICOM Server
Vendor:
Orthanc
Product Version:
Orthanc Orthanc DICOM Server: <1.13.0.
Product Status:
known_affected
Relevant CWE: CWE-190 Integer Overflow or Wraparound
Metrics
| CVSS Version | Base Score | Base Severity | Vector String |
|---|---|---|---|
| 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| 4.0 | 7.2 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Acknowledgments
- Andrej Tomci reported this vulnerability to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.
Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Locate control system networks and remote devices behind firewalls and isolating them from business networks.
When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
Do not click web links or open attachments in unsolicited email messages.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-10
| Date | Revision | Summary |
|---|---|---|
| 2026-09-10 | 1 | Initial Publication |
Legal Notice and Terms of Use
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02