VulnerabilitiesOrthanc DICOM Server Flaw Allows Authenticated Attackers to Corrupt Heap Memory
CVE-2026-87020 lets authenticated attackers crash Orthanc DICOM Server <1.13.0 via malicious PNG causing heap overflow. Learn impact and fixes.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesCVE-2026-87020 lets authenticated attackers crash Orthanc DICOM Server <1.13.0 via malicious PNG causing heap overflow. Learn impact and fixes.
VulnerabilitiesCISA expanded its iDirect advisory with two new flaws exposing credential hashes and enabling critical local privilege escalation on satellite terminals.
VulnerabilitiesCISA warns of four AVEVA Pipeline Integrity Monitor flaws enabling data theft, credential recovery and XSS. Update to 2025 SP1 P2 and reset passwords.
VulnerabilitiesGitLab CVE-2026-85706 allows unauthenticated file access via API. CISA added it to KEV with Sept 14 deadline. Learn affected versions and fixes.
VulnerabilitiesUnauthenticated GitLab flaw CVE-2026-85706 (CVSS 10) exploited within a day. Learn affected versions, detection logs and patch deadline.
VulnerabilitiesUK council cyberattack linked to mass exploitation of CVE-2026-15409 in SonicWall SMA1000, enabling credential theft and Active Directory compromise.
VulnerabilitiesAttackers chain JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 to gain admin access, install Groovy plugins and Rust backdoor. Patch now.
VulnerabilitiesCISA discloses three high-severity Mirth Connect flaws through 4.7.1, with SQL injection and XXE risking data theft and credential exposure.
VulnerabilitiesShieldCrash PoC claims bypass of Microsoft's fix for CVE-2026-69414, enabling SYSTEM-level file reads on patched Windows via Defender.
VulnerabilitiesCisco FMC zero-auth flaws exploited by Qilin ransomware, Sandworm-linked hackers, and a third cluster for ransomware, credential theft, and espionage.
VulnerabilitiesCheck Point fixes two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, with CVSS 9.8, enabling unauthenticated RCE on Security Gateways and Management.
VulnerabilitiesCISA confirms critical WatchGuard Firebox RCE CVE-2025-14733 is exploited in ransomware attacks. Learn affected versions, risks, and patch guidance.