RadiAnt DICOM: JPEG File Vulnerability Could Compromise the Application

On 2026-08-06, CISA published an advisory on CVE-2026-17264 , a vulnerability in Medixant RadiAnt DICOM , software used to view medical images in the

RadiAnt DICOM: JPEG File Vulnerability Could Compromise the Application
Vulnerabilities

Illustrative image generated with AI

Vulnerability Identified in Medical Imaging Viewer

On 2026-08-06, CISA published an advisory on CVE-2026-17264, a vulnerability in Medixant RadiAnt DICOM, software used to view medical images in the Healthcare and Public Health sector.

The flaw is classified as CWE-787, Out-of-bounds Write. All versions up to and including 2025.2 are affected.

The vulnerability could affect deployments worldwide. Medixant is based in Poland.

Crafted DICOM File Can Trigger an Out-of-Bounds Write

The attack relies on a specially crafted DICOM file containing malicious JPEG pixel data. When the file is opened in RadiAnt DICOM, processing may write data beyond the allocated heap buffer.

This could cause the application to crash. The technical description also indicates potential remote code execution, although the impact documented by the CVSS scores primarily concerns application availability.

User interaction is required: the file must be opened. However, the attack vector is classified as network-reachable and does not require privileges.

Medium Severity, but a Real Risk for Healthcare Environments

The vulnerability has a CVSS 3.1 score of 4.3, rated MEDIUM:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

The CVSS 4.0 score is 5.3, also rated MEDIUM:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

The risk affects workstations and systems used to view diagnostic images. A malicious file could disrupt the viewer’s operation; in a more advanced exploitation scenario, it could lead to further consequences on the system running the software.

There are currently no known reports of this vulnerability being actively exploited in the wild.

Available Mitigations and Outstanding Information

No fixed version or specific patch has been identified. Administrators should therefore:

  • limit network exposure and block direct Internet access;
  • isolate systems and remote devices from corporate networks using firewalls;
  • use up-to-date VPNs for remote access, while also assessing the security of connected devices;
  • avoid opening DICOM attachments received in unexpected messages;
  • implement protections against phishing and social engineering;
  • apply segmentation, defense-in-depth, and monitoring across healthcare assets;
  • assess the operational impact before making infrastructure changes;
  • report any suspicious activity according to corporate procedures.

The vulnerability was reported to CISA by banda, oriotie, ax123, jihyeon4725, lacroix, and minzu.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →