CISA has published ICS Medical Advisory ICSMA-26-253-02 covering CVE-2026-87020, an integer overflow in Orthanc's pitch and buffer-size computation that leads to a heap out-of-bounds write when the server decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The flaw is rated CVSS 8.1 and affects Orthanc DICOM Server versions below 1.13.0; exploitation requires authenticated remote access, and CISA reports no known public exploitation at the time of publication. Orthanc is an open-source DICOM server widely embedded in imaging workflows in hospitals and research settings precisely because it is lightweight and free, which means it is frequently deployed by clinical engineering teams without a formal vendor patch relationship. The advisory is one of three CISA published on 10 September covering clinical integration and imaging software โ the others being ICSMA-26-253-01 for NextGen Healthcare Mirth Connect, reported in yesterday's digest, and an ICS advisory for AVEVA Pipeline Integrity Monitor โ and the cluster is a useful marker of how much of healthcare's attack surface is now made up of open-source and embedded components that no single supplier tracks.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-12 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-87020 |