{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/orthanc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Orthanc DICOM Server (\u003c1.13.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ics-medical","dos"],"_cs_type":"advisory","_cs_vendors":["Orthanc"],"content_html":"\u003cp\u003eOrthanc DICOM Server versions prior to 1.13.0 are susceptible to a heap out-of-bounds write vulnerability, tracked as CVE-2026-87020. The vulnerability stems from an integer overflow in the pitch and buffer-size computation logic when the server decodes PNG or JPEG images. An authenticated remote attacker can exploit this flaw by submitting a specially crafted image file to the DICOM server. Successful exploitation results in memory corruption, leading to a process crash and a denial-of-service (DoS) condition. This vulnerability poses a significant risk to healthcare environments where Orthanc is deployed to manage sensitive medical imaging data, as the crash disrupts the availability of critical imaging services. Organizations are advised to update to version 1.13.0 to remediate this flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects the Healthcare and Public Health sector globally. A successful attack results in the termination of the Orthanc service, preventing clinicians and medical systems from accessing or processing DICOM imagery. Given the dependency of modern radiology workflows on PACS and image management servers like Orthanc, this disruption can directly impact patient care and diagnostic throughput.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Orthanc DICOM Server to version 1.13.0 or later immediately to patch CVE-2026-87020.\u003c/li\u003e\n\u003cli\u003eMinimize network exposure by isolating DICOM servers from the public internet and ensuring access is restricted to authorized internal networks only.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to place medical imaging infrastructure behind firewalls, restricting direct communication between the DICOM server and non-essential business segments.\u003c/li\u003e\n\u003cli\u003eEnforce strict authentication controls for the Orthanc web API to reduce the likelihood of unauthenticated or unauthorized users submitting malicious payloads.\u003c/li\u003e\n\u003cli\u003eMonitor Orthanc application logs for recurring service restarts or unexpected process crashes that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T16:06:45Z","date_published":"2026-09-10T16:06:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-orthanc-dicom-dos/","summary":"An integer overflow vulnerability (CVE-2026-87020) in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to cause a denial-of-service via a crafted PNG or JPEG image.","title":"Heap Out-of-Bounds Write Vulnerability in Orthanc DICOM Server","url":"https://feed.craftedsignal.io/briefs/2026-09-orthanc-dicom-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Orthanc","version":"https://jsonfeed.org/version/1.1"}