What Happened
CISA has disclosed a critical vulnerability (CVE-2026-17264, CVSS 4.3) in Medixant's RadiAnt DICOM viewer, a medical imaging application deployed worldwide. The flaw involves a heap out-of-bounds write triggered when opening specially crafted DICOM files with malicious JPEG-compressed pixel data. Successful exploitation could allow remote code execution, though the application does include exploit mitigation controls like Control Flow Guard and DEP.
Why SMBs Should Care
While this primarily affects healthcare organizations, the attack vector is a reminder of the risks posed by file-based exploits across all industries. Any SMB working with healthcare clients, handling medical imaging data, or providing IT services to clinical environments should verify that RadiAnt DICOM is updated to version 2026.1. Beyond patching, this incident underscores the importance of vendor risk management and file handling policies—malicious files remain a common entry point for ransomware and other attacks. Organizations should enforce strict controls around opening files from untrusted sources and maintain current inventories of all software in their environments, especially applications that process external data formats.
Need help assessing your vendor risk or hardening your infrastructure against file-based attacks? O-Cyrus provides practical security assessments and infrastructure management for SMBs. Contact our team or explore our security services.
Need a hand with this?
O-Cyrus helps small businesses with websites, DNS, custom apps, and the everyday tech that keeps things running.
Talk to us →