- What is CVE-2026-87020?
- Organizations should upgrade Orthanc DICOM Server to version 1.13.0 or later, as recommended by the vendor. Additionally, CISA advises minimizing network exposure of control systems and medical devices, ensuring they are not accessible from the internet, and placing them behind firewalls isolated from business networks. When remote access is necessary, use secure methods such as VPNs, and keep all systems updated. Perform impact analysis and risk assessment before deploying defensive measures.
- How severe is CVE-2026-87020?
- high, CVSS 8.1
- Is CVE-2026-87020 known to be exploited?
- It is not marked known-exploited in this record.
- How should CVE-2026-87020 be mitigated?
- Organizations should upgrade Orthanc DICOM Server to version 1.13.0 or later, as recommended by the vendor. Additionally, CISA advises minimizing network exposure of control systems and medical devices, ensuring they are not accessible from the internet, and placing them behind firewalls isolated from business networks. When remote access is necessary, use secure methods such as VPNs, and keep all systems updated. Perform impact analysis and risk assessment before deploying defensive measures.