CVE-2026-87020: Orthanc Dicom Server

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

Affected products

  • Orthanc Dicom Server: before 1.13.0 (fixed in 1.13.0)

Published 2026-09-11. Last modified 2026-09-18.