# RadiAnt DICOM viewer heap overflow flaw patched

Published: 2026-08-06 · Severity: medium · Sectors: healthcare
Canonical: https://vorant.io/reports/1d0a9ec0-a7e7-5282-bc96-d1f16b74f1cd/radiant-dicom-viewer-heap-overflow-flaw-patched

> A heap out-of-bounds write in Medixant RadiAnt DICOM viewer lets attackers achieve remote code execution via a crafted DICOM file; no exploitation reported.

CISA disclosed a vulnerability in Medixant RadiAnt DICOM, a medical imaging viewer used worldwide across healthcare and public health organizations. The flaw, CVE-2026-17264, stems from improper handling of JPEG-compressed pixel data within DICOM files, triggering an attacker-controlled heap out-of-bounds write (CWE-787) that could allow remote code execution or application crash when a maliciously crafted file is opened.

Affected versions are RadiAnt DICOM 2025.2 and earlier. Medixant, headquartered in Poland, has released version 2026.1 to address the issue. Built-in exploit mitigations such as CFG, DEP, and ASLR reduce practical exploitability, and CISA notes no known public exploitation targeting this vulnerability at this time. Organizations should update promptly, avoid opening DICOM files from untrusted sources, and follow standard ICS network segmentation and remote access hardening practices.

## Mentioned in this report

- Vulnerabilities: CVE-2026-17264

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1d0a9ec0-a7e7-5282-bc96-d1f16b74f1cd/radiant-dicom-viewer-heap-overflow-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
