VORANT. Threat Intelligence Sign in Get the full feed

RadiAnt DICOM viewer heap overflow flaw patched

medium vulnerability healthcare

A heap out-of-bounds write in Medixant RadiAnt DICOM viewer lets attackers achieve remote code execution via a crafted DICOM file; no exploitation reported.

CISA disclosed a vulnerability in Medixant RadiAnt DICOM, a medical imaging viewer used worldwide across healthcare and public health organizations. The flaw, CVE-2026-17264, stems from improper handling of JPEG-compressed pixel data within DICOM files, triggering an attacker-controlled heap out-of-bounds write (CWE-787) that could allow remote code execution or application crash when a maliciously crafted file is opened.

Affected versions are RadiAnt DICOM 2025.2 and earlier. Medixant, headquartered in Poland, has released version 2026.1 to address the issue. Built-in exploit mitigations such as CFG, DEP, and ASLR reduce practical exploitability, and CISA notes no known public exploitation targeting this vulnerability at this time. Organizations should update promptly, avoid opening DICOM files from untrusted sources, and follow standard ICS network segmentation and remote access hardening practices.

Mentioned in this report

Vulnerabilities CVE-2026-17264

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free