Orthanc DICOM Server
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server <1.13.0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or Wraparound Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Belgium Vulnerabilities Expand All + CVE-2026-87020 An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG. View CVE Details Affected Products Orthanc DICOM Server Vendor: Orthanc Product Version: Orthanc DICOM Server: <1.13.0. Product Status: known_affected Remediations Mitigation Orthanc recommends users update to v1.13.0. https://orthanc.uclouvain.be/downloads/index.html Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Andrej Tomci reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote
Details
Original advisory: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-87020 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Orthanc DICOM Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-11
- highCISA Adds Three Known Exploited Vulnerabilities to Catalog2026-09-11
- criticalST Engineering iDirect iQ-Series Terminals (Update A)2026-09-10
- criticalCISA Adds Two Known Exploited Vulnerabilities to Catalog2026-09-10
- criticalNextGen Healthcare Mirth Connect2026-09-10