Several high-severity vulnerabilities have been disclosed in the OFFIS DCMTK Toolkit, a widely used DICOM implementation for medical imaging workflows, including a critical path traversal flaw tracked as CVE-2026-50003. That issue allows a malicious or compromised server to make a DCMTK client using bit-preserving C-GET storage mode write files outside the intended output directory via relative ../ or absolute paths. Another path traversal bug, CVE-2026-52868, lets an unauthenticated remote attacker read worklist records from directories outside the intended per-AE worklist storage area, potentially exposing sensitive patient or departmental data across organizational boundaries in multi-area deployments.
Additional remotely exploitable flaws can also disrupt DCMTK services. CVE-2026-50254 and CVE-2026-35505 are memory-leak issues that allow repeated crafted connection requests to exhaust memory and crash single-process deployments such as storescp, while CVE-2026-44628 is a type confusion vulnerability that can crash the worklist server with a single crafted query under specific conditions. Reported severity ranges up to CVSS 9.8 under v3.1 and 9.3 under v4.0, and recommended mitigations include updating DCMTK, validating and sanitizing file paths and inputs, restricting worklist storage access, using stronger access controls, and considering multi-process operation to reduce denial-of-service impact.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic published an advisory for Fleet Server versions 8.19.11, 9.2.5, and 9.3.0 titled ESA-2026-44. The provided reference confirms the advisory's publication but does not include further technical details in the synopsis.
Five remotely exploitable vulnerabilities affecting the OFFIS DCMTK Toolkit were published: CVE-2026-52868, CVE-2026-50254, CVE-2026-50003, CVE-2026-44628, and CVE-2026-35505. The issues include path traversal, memory leak denial of service, and type confusion flaws, with recommended mitigations centered on updating, input validation, and access restrictions.
On the oss-sec mailing list, five vulnerabilities affecting OFFIS DCMTK 3.7.0 and earlier were disclosed as part of CISA advisory ICSMA-26-181-01 and CERT/CC case VU#470252. The post said fixes had been committed to the upstream master branch but were not yet included in a released version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
8 references tracked. Mallory keeps watching after this page renders.
discuss.elastic.co
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.