CISA warns Orthanc DICOM Server heap overflow allows denial of service
CISA published an advisory for CVE-2026-87020, an integer overflow in Orthanc DICOM Server before 1.13.0. An authenticated remote attacker can trigger a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG, crashing the process and causing denial of service. Orthanc recommends updating to v1.13.0. CVSS 3.1 base score is 8.1.
Sources and evidence
Attributed quotes
“Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.”
“An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.”
“Orthanc recommends users update to v1.13.0.”
Summary last validated Sep 10, 2026
Reader actions
Report an issue
Use this for an incorrect summary, wrong source, duplicate story, or wrong category. Submissions are private and do not change the story automatically.
Related coverage
- security
Microsoft urges early testing of post-quantum certificate ecosystems
Microsoft published guidance urging organizations to begin testing certificate ecosystems for post-quantum authentication now, highlighting its PQC TLS Pilot Program as a way to advance future readiness. The post appeared on the Microsoft Security Blog.
- security
CISA: Chinese Government-linked Hackers Target US Critical Infrastructure
CISA published an advisory stating Chinese government-linked cyber threat actors, enabled by China-based Integrity Technology Group, combine automated scanning, botnets, and hands-on exploitation to steal sensitive data from organizations worldwide, including US critical infrastructure. Tactics include cross-site scripting and password spraying on Microsoft Exchange servers, VPN persistence, and email and credential exfiltration via scripts.
- security
Cisco Talos Ties UAT-11985 to AI-Assisted Google AitM Phishing
Cisco Talos identified an APT spear-phishing campaign, tracked as UAT-11985, targeting individuals affiliated with Taiwan research organizations. The operation used legitimate public event themes and impersonated reputable academic and policy institutions, delivering real-time Google adversary-in-the-middle phishing.
- security
Cisco Talos details malware techniques for evading AI analysis
Cisco Talos published research on "AI-analysis evasion," describing real-world techniques malware authors use to obstruct or defeat automated AI analysis layers. The blog examines the current state of these evasion methods, which are designed to interfere with AI-driven malware detection and analysis pipelines.
- security
Anthropic launches Cyber Mission with Critical Infrastructure Defense Program and OSS Scanner
Anthropic announced the Anthropic Cyber Mission, a long-term effort to help defenders secure software and systems. It starts with two programs: the Critical Infrastructure Defense Program, providing frontier models, on-site engineers, and threat research for operational technology like power grids and water systems, and OSS Scanner, offering open-source projects free security scans from Anthropic's strongest models.