Internet-facing medical-imaging deployments running Orthanc PACS administrative consoles and OHIF web viewers were found exposed through HTTP/S interfaces, creating potential access to sensitive imaging records. Passive scanning identified 414 reachable Orthanc consoles and 700 OHIF viewers; in the United States, 36 of 91 identified Orthanc consoles—about 40%—accepted access without an authentication challenge, while 43 were protected and 12 could not be conclusively classified.
The exposure is linked to insecure deployment defaults, including reuse of a canonical OHIF-Orthanc Docker configuration. CVE-2025-0896 documents that Orthanc does not enable authentication by default when remote access is enabled. The exposed systems appear more likely to belong to smaller self-hosted radiology and pathology practices than enterprise hospital environments, underscoring the need to restrict public access, require authentication, and review internet-exposed DICOM and imaging-management services.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Using passive data collected on June 29, 2026, researchers identified 414 internet-reachable Orthanc administrative consoles and 700 OHIF medical-image viewers on HTTP/S web ports. In the United States, 36 of 91 observed Orthanc consoles were confirmed accessible without an authentication challenge.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.