All stories
criticalExploited VulnerabilitiesCVE-2026-50003CVE-2026-50254CVE-2026-35505CVE-2026-52868CVE-2026-44628

Critical Vulnerabilities in DCMTK Toolkit Threaten Medical Imaging Systems; Urgent Patch Required

The DCMTK Toolkit has been identified with multiple critical vulnerabilities that could allow attackers to manipulate file directories, leak memory, and crash worklist servers. These issues pose significant risks to medical imaging systems using the toolkit. Immediate patching is advised for all affected installations.

Summary

A series of critical vulnerabilities have been disclosed in the DCMTK Toolkit, a widely used software package for handling DICOM (Digital Imaging and Communications in Medicine) files. The vulnerabilities, identified as CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, and CVE-2026-44628, range from critical to high severity. These flaws could enable attackers to manipulate file directories, leak memory, and crash worklist servers, potentially disrupting medical imaging services.

What Happened

The vulnerabilities were disclosed by the vendor OFFIS DICOM in a coordinated release of patches. The most severe issue, CVE-2026-50003, allows an attacker to make a DCMTK client write files outside the intended directory using both relative and absolute paths. This could lead to unauthorized data manipulation or access.

Technical Details

CVE-2026-50254 and CVE-2026-35505 involve memory leakage vulnerabilities that can be exploited by sending crafted connection requests. These attacks can cause services to crash, leading to denial of service. CVE-2026-52868 allows attackers to read worklist records from unauthorized directories, potentially breaching data separation protocols in multi-area deployments.

Affected Products and Fixed Versions

The DCMTK Toolkit is affected across various versions, with patches available for the latest release. Organizations using this toolkit should verify their current version against the vendor's release notes and apply updates immediately to mitigate these vulnerabilities.

Exploitation Status

While there are no confirmed reports of exploitation in the wild, the severity of these vulnerabilities makes them attractive targets for attackers. The lack of a known exploited status does not diminish the urgency for patching.

Indicators of Compromise

No specific indicators of compromise (IOCs) have been published alongside these advisories. Organizations should monitor their systems for unusual activity that could suggest exploitation attempts, such as unexpected file writes or service crashes.

Detection Opportunities

Organizations can detect potential exploitation by monitoring network traffic for unusual patterns of connection requests to the affected services and checking system logs for unauthorized file access attempts.

Timeline

The vulnerabilities were disclosed on June 25, 2026, with patches released shortly thereafter. Organizations are urged to apply these patches as soon as possible to protect their systems from potential attacks.

Why This Matters for Defenders

For defenders, the disclosure of these vulnerabilities underscores the importance of timely patch management and monitoring for unusual system behavior. The critical nature of medical imaging services means that any disruption could have significant consequences, making it imperative to address these vulnerabilities promptly.

What Remains Unclear

While patches are available, it remains unclear how widespread the use of vulnerable versions of the DCMTK Toolkit is across different organizations. Additionally, there is no information on whether attackers have already begun exploiting these vulnerabilities before their public disclosure.

Defender Guidance

Defenders should immediately review their installations of the DCMTK Toolkit for affected versions and apply the necessary patches as outlined in the vendor's release notes. Monitoring systems for signs of exploitation attempts and unusual activity can also help in early detection and mitigation of potential attacks. Organizations are encouraged to conduct a thorough security assessment to ensure that all components of their medical imaging infrastructure are secure.

Hashtags

#h4rithd, #news, #HarithDilshan, OFFIS DICOM, DCMTK Toolkit, CVE-2026-50003, CVE-2026-50254

Sources

  1. https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01
  2. https://github.com/DCMTK/dcmtk/releases/tag/latest
  3. https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-181-01.json
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -