Users should update to Medixant RadiAnt DICOM version 2026.1, available at https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe. Additionally, only open DICOM files from trusted and reliable sources. CISA recommends minimizing network exposure for medical devices, using firewalls and VPNs for remote access, and following general security practices to avoid social engineering attacks.
Quick answers
What is CVE-2026-17264?
Users should update to Medixant RadiAnt DICOM version 2026.1, available at https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe. Additionally, only open DICOM files from trusted and reliable sources. CISA recommends minimizing network exposure for medical devices, using firewalls and VPNs for remote access, and following general security practices to avoid social engineering attacks.
How severe is CVE-2026-17264?
medium, CVSS 4.3
Is CVE-2026-17264 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-17264 be mitigated?
Users should update to Medixant RadiAnt DICOM version 2026.1, available at https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe. Additionally, only open DICOM files from trusted and reliable sources. CISA recommends minimizing network exposure for medical devices, using firewalls and VPNs for remote access, and following general security practices to avoid social engineering attacks.
CVSS
4.3
Vendor
Medixant
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Medixant RadiAnt DICOM
Mitigation
Users should update to Medixant RadiAnt DICOM version 2026.1, available at https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe. Additionally, only open DICOM files from trusted and reliable sources. CISA recommends minimizing network exposure for medical devices, using firewalls and VPNs for remote access, and following general security practices to avoid social engineering attacks.
CISA has published an advisory (ICSMA-26-218-01) detailing CVE-2026-17264, a heap out-of-bounds write vulnerability in Medixant RadiAnt DICOM versions 2025.2 and earlier. Successful exploitation requires a user to open a maliciously crafted DICOM file containing JPEG-compressed pixel data, potentially leading to application crash or remote code execution. The vendor has released version 2026.1 to address the issue. No public exploitation has been reported.