highOther

Orthanc DICOM Server Heap Out-of-Bounds Write via Integer Overflow in Image Decoding (CVE-2026-87020)

First seen Sep 11, 2026 · Updated Sep 11, 2026 · CVSS 8.1

ICSmedical-deviceDICOMhealthcareinteger-overflowdenial-of-serviceheap-overflowCISA-advisory

Orthanc DICOM Server versions prior to 1.13.0 contain an integer overflow vulnerability in pitch/buffer-size computation that leads to a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can exploit this to crash the Orthanc process, causing a denial-of-service condition affecting medical imaging availability.

Technical Analysis

CVE-2026-87020 (CWE-190, CVSS v3.1 8.1) is an integer overflow occurring during buffer-size and pitch calculations when Orthanc parses attacker-supplied PNG or JPEG image data, resulting in a heap out-of-bounds write. Exploitation requires low-privilege authentication and no user interaction, and can be triggered remotely over the network (AV:N, PR:L, UI:N), causing the Orthanc process to crash and disrupting availability of DICOM imaging services. No known public exploitation has been reported to CISA at this time. This vulnerability does not have plausible direct relevance to AI agent systems, as Orthanc is a medical imaging server rather than infrastructure typically embedded in agent/LLM tool-use pipelines; however, healthcare organizations that integrate Orthanc into automated imaging-analysis or agentic diagnostic workflows should be aware that a crash could disrupt those pipelines' data sources.

Affected Systems

Orthanc DICOM Server versions prior to 1.13.0, deployed worldwide primarily in Healthcare and Public Health sector environments

Indicators of Compromise

  • No specific IOCs published; vulnerability tracked as CVE-2026-87020

Remediation Steps

  1. 1

    Upgrade Orthanc

    Update Orthanc DICOM Server to version 1.13.0 or later, available at https://orthanc.uclouvain.be/downloads/index.html

  2. 2

    Network segmentation

    Minimize network exposure for control system devices; ensure Orthanc servers are not accessible directly from the internet and are placed behind firewalls, isolated from business networks

  3. 3

    Secure remote access

    Use VPNs or other secure remote access methods when remote connectivity to imaging systems is required, keeping VPN software updated

  4. 4

    Monitor and report

    Monitor for abnormal crashes or DoS conditions on Orthanc instances and report suspected malicious activity to CISA for tracking

CVE / Advisory IDs

CVE-2026-87020

Industries Most Exposed

Healthcare and Public Health

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.