VORANT. Threat Intelligence Sign in Get the full feed

Orthanc DICOM Server heap overflow flaw patched

routine vulnerability healthcare

An authenticated attacker can crash Orthanc DICOM Server via a malicious PNG/JPEG, causing denial of service; patch to v1.13.0.

CISA published an ICS Medical Advisory for Orthanc DICOM Server, an open-source medical imaging server used worldwide in healthcare settings. The vulnerability, CVE-2026-87020, is an integer overflow (CWE-190) in the pitch/buffer-size computation used when decoding attacker-supplied PNG or JPEG images. This leads to a heap out-of-bounds write, which can crash the Orthanc process and create a denial-of-service condition. Exploitation requires the attacker to be authenticated and to supply a crafted image to the server.

All versions of Orthanc DICOM Server prior to 1.13.0 are affected. The vendor (Orthanc, headquartered in Belgium) recommends upgrading to v1.13.0, available from the official Orthanc downloads page. CISA states no known public exploitation targeting this vulnerability has been reported at this time, and standard ICS network-hardening guidance (segmentation, no direct internet exposure, VPN for remote access) applies. Given the DoS-only impact, authentication requirement, and lack of known exploitation, this is a routine patch-and-mitigate advisory rather than an urgent threat.

Defenders operating Orthanc DICOM servers in clinical or PACS environments should prioritize upgrading to 1.13.0+, ensure the management interface is not internet-facing, and monitor for unexpected process crashes or restarts that could indicate exploitation attempts.

Mentioned in this report

Vulnerabilities CVE-2026-87020

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free