HomeIntelligenceBrief
VULNERABILITY BRIEF🟢 Low Vulnerability

Out‑of‑Bounds Write (CVE‑2026‑17264) in Medixant RadiAnt DICOM Viewer Allows Remote Code Execution

CISA has issued an advisory for a vulnerability (CVE‑2026‑17264) in Medixant RadiAnt DICOM Viewer versions ≤2025.2. A crafted DICOM file can trigger an out‑of‑bounds heap write, potentially enabling remote code execution. For healthcare organizations, this underscores the need for timely patching and evidence of control remediation to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 cisa.gov
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Out‑of‑Bounds Write (CVE‑2026‑17264) in Medixant RadiAnt DICOM Viewer Allows Remote Code Execution

What It Is — A heap out‑of‑bounds write triggered by a maliciously crafted DICOM file can let an attacker execute arbitrary code on systems running Medixant RadiAnt DICOM Viewer ≤ 2025.2.

Exploitability — CVSS v3 4.3 (Low). Exploits exist in the wild; the vendor notes that built‑in mitigations (CFG, DEP, ASLR) reduce practical exploitability, but successful exploitation remains possible.

Affected Products — Medixant RadiAnt DICOM Viewer ≤ 2025.2 (all platforms).

Why It Matters for Compliance & Audit Readiness

  • Patch management is a core SOC 2 CC6.1 control; undocumented or delayed updates constitute a control gap that auditors will flag.
  • Demonstrating that only trusted DICOM sources are processed satisfies the “System Operations” criteria for change and access controls.
  • Continuous evidence of remediation (patch version, mitigation status) feeds directly into a Trust Center audit trail, reducing “under‑investigation” findings during SOC 2 examinations.

Recommended Actions

  • Upgrade all RadiAnt installations to version 2026.1 immediately.
  • Enforce a policy to open DICOM files only from verified, trusted sources.
  • Capture patch‑install logs and mitigation settings (CFG, DEP, ASLR) as SOC 2 evidence.
  • Map the vulnerability to the relevant SOC 2 control (CC6.1 – System Operations) and record remediation in your continuous‑compliance platform.

Source: CISA Advisory ICS‑MA‑26‑218‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →