Medixant RadiAnt DICOM Viewer installations running version 2025.2 or earlier should be updated to 2026.1 immediately after CISA disclosed CVE-2026-17264, a heap out-of-bounds write triggered by opening a malicious DICOM file with JPEG-compressed pixel data. CISA says the flaw can crash the application and describes an attacker-controlled memory write that may permit arbitrary code execution; no public exploitation has been reported as of August 6, 2026.
The immediate operational point for Windows administrators is straightforward: this is a client-side file-parsing flaw, not a vulnerability that requires a RadiAnt service to be exposed directly to the internet. The attacker’s practical route is to get a crafted imaging study onto a workstation and have a user open it. In healthcare environments, that can mean a file from removable media, an email attachment, a shared folder, an archive, or a PACS-connected workflow—not merely an obviously suspicious
CISA’s advisory covers all releases through RadiAnt DICOM Viewer 2025.2 and directs users to version 2026.1. Medixant’s own version history confirms that 2026.1 was built on July 14, 2026, and includes a terse fix for a crash caused by a malformed DICOM file. The public vendor notes do not name CVE-2026-17264 or explain that the malformed data is JPEG-compressed pixel content, leaving CISA’s advisory as the only public account of the underlying memory-safety issue.
CISA classifies CVE-2026-17264 as CWE-787, an out-of-bounds write. Its technical description is materially more serious than the executive summary: opening a crafted DICOM image can produce an attacker-controlled heap write and may allow arbitrary code execution. That is the kind of vulnerability class administrators should treat as a patch-now issue in a viewer used to open externally supplied clinical data.
Yet the published CVSS ratings are only medium: 4.3 under CVSS 3.1 and 5.3 under CVSS 4.0. The reason is visible in the vectors. They assign no confidentiality or integrity impact and only low availability impact; the CVSS 3.1 vector also requires user interaction. In other words, the score models a low-impact application crash after a user opens the file, even as the narrative preserves the possibility that controlled heap corruption could go further.
That is a real mismatch in the public record, not a reason to dismiss the issue. A CVSS score is a standardized severity estimate, while an out-of-bounds write can have a wider range of real-world outcomes depending on the process architecture, the exact corruption primitive, available mitigations, and the attacker’s ability to shape memory state. CISA says RadiAnt is built with Control Flow Guard, Data Execution Prevention, and Address Space Layout Randomization, and Medixant characterizes those safeguards as significantly reducing exploitability. They raise the bar; they do not repair the vulnerable parser in older builds.
The safer interpretation is that a reliable crash is the confirmed effect, while code execution is a plausible but not publicly demonstrated outcome. Healthcare IT teams should not wait for a proof of concept or a higher CVSS number before replacing the affected build.
That feature set explains why the user-interaction requirement should not be read narrowly. A victim must open the malicious study, but in a normal imaging workflow “open” can be an ordinary clinical action: reviewing a referral CD, loading a study received through a shared location, importing an archive, or examining an unfamiliar study delivered through an established imaging channel. The file need not masquerade as an executable, and Windows’ usual warning prompts for downloaded programs do not apply to an image study opened by a trusted viewer.
The flaw specifically involves JPEG-compressed pixel data within a DICOM object. That is important because content filtering built around file extensions has little value here. A DICOM file can retain its expected extension and metadata while embedding malicious image data in the compressed-pixel stream. The protective control is therefore a fixed viewer, paired with sensible handling rules for studies from sources outside an organization’s established PACS and referral process.
Medixant’s product documentation also shows that RadiAnt can work with a local archive and imports from removable drives and network locations. Workstations used for ad hoc review—radiology reading stations, clinical research PCs, support desktops, and patient-media review systems—may be more exposed than a tightly managed PACS server, because they are more likely to encounter files from outside the main imaging pipeline.
This timing suggests the fix had already shipped before the coordinated disclosure became public. The vendor’s short release note is normal for a small desktop application, but it creates an inventory problem: an administrator looking only for a security-labelled release or a matching CVE will not find one in the change log. The build appears as a generic maintenance release, despite now being the remediation for a CISA-published vulnerability.
There is another deployment complication. Medixant’s version-history page tells customers to sign in to their license account to obtain the version covered by their license. The public records reviewed do not spell out whether every existing 2025.2 installation is entitled to 2026.1, whether any update channel deploys it automatically, or whether the portable CD/DVD/USB package is built from the same fixed code. Organizations should verify this rather than assuming an installed copy will self-update.
The distinction matters most for managed environments. The current CISA advisory identifies the affected product as “Medixant RadiAnt DICOM,” while Medixant markets it as “RadiAnt DICOM Viewer.” Asset inventories may use either name, and some software catalogs may report the year-based version as
A practical response should include the following actions:
The decisive date for administrators is July 14, 2026: that is when Medixant built RadiAnt DICOM Viewer 2026.1, the release CISA identifies as the fix. Any workstation still on 2025.2 or an earlier release remains exposed every time a user opens an untrusted JPEG-compressed DICOM study.
.dcm file downloaded from the web.CISA’s advisory covers all releases through RadiAnt DICOM Viewer 2025.2 and directs users to version 2026.1. Medixant’s own version history confirms that 2026.1 was built on July 14, 2026, and includes a terse fix for a crash caused by a malformed DICOM file. The public vendor notes do not name CVE-2026-17264 or explain that the malformed data is JPEG-compressed pixel content, leaving CISA’s advisory as the only public account of the underlying memory-safety issue.
The advisory and the vendor release describe different levels of risk
CISA classifies CVE-2026-17264 as CWE-787, an out-of-bounds write. Its technical description is materially more serious than the executive summary: opening a crafted DICOM image can produce an attacker-controlled heap write and may allow arbitrary code execution. That is the kind of vulnerability class administrators should treat as a patch-now issue in a viewer used to open externally supplied clinical data.Yet the published CVSS ratings are only medium: 4.3 under CVSS 3.1 and 5.3 under CVSS 4.0. The reason is visible in the vectors. They assign no confidentiality or integrity impact and only low availability impact; the CVSS 3.1 vector also requires user interaction. In other words, the score models a low-impact application crash after a user opens the file, even as the narrative preserves the possibility that controlled heap corruption could go further.
That is a real mismatch in the public record, not a reason to dismiss the issue. A CVSS score is a standardized severity estimate, while an out-of-bounds write can have a wider range of real-world outcomes depending on the process architecture, the exact corruption primitive, available mitigations, and the attacker’s ability to shape memory state. CISA says RadiAnt is built with Control Flow Guard, Data Execution Prevention, and Address Space Layout Randomization, and Medixant characterizes those safeguards as significantly reducing exploitability. They raise the bar; they do not repair the vulnerable parser in older builds.
The safer interpretation is that a reliable crash is the confirmed effect, while code execution is a plausible but not publicly demonstrated outcome. Healthcare IT teams should not wait for a proof of concept or a higher CVSS number before replacing the affected build.
The attack surface follows how RadiAnt handles studies
RadiAnt is a Windows DICOM viewer designed to handle more than a manually selected local file. Medixant lists support for JPEG Lossy, JPEG Lossless, JPEG 2000, JPEG-LS, RLE, and uncompressed DICOM images. It also supports opening studies from local and network folders, USB media, optical media, and ZIP archives, while its full edition can retrieve studies from PACS locations and receive incoming studies pushed from other PACS systems.That feature set explains why the user-interaction requirement should not be read narrowly. A victim must open the malicious study, but in a normal imaging workflow “open” can be an ordinary clinical action: reviewing a referral CD, loading a study received through a shared location, importing an archive, or examining an unfamiliar study delivered through an established imaging channel. The file need not masquerade as an executable, and Windows’ usual warning prompts for downloaded programs do not apply to an image study opened by a trusted viewer.
The flaw specifically involves JPEG-compressed pixel data within a DICOM object. That is important because content filtering built around file extensions has little value here. A DICOM file can retain its expected extension and metadata while embedding malicious image data in the compressed-pixel stream. The protective control is therefore a fixed viewer, paired with sensible handling rules for studies from sources outside an organization’s established PACS and referral process.
Medixant’s product documentation also shows that RadiAnt can work with a local archive and imports from removable drives and network locations. Workstations used for ad hoc review—radiology reading stations, clinical research PCs, support desktops, and patient-media review systems—may be more exposed than a tightly managed PACS server, because they are more likely to encounter files from outside the main imaging pipeline.
Version 2026.1 was available before CISA published the CVE
CISA published the medical advisory on August 6, 2026. Medixant’s version history dates the fixed 2026.1 release to July 14, 2026—23 days earlier. Its change log says only that it fixed a crash when opening a certain type of malformed DICOM file, alongside display fixes for obscure nonconformant DICOM files and a window-size restoration issue.This timing suggests the fix had already shipped before the coordinated disclosure became public. The vendor’s short release note is normal for a small desktop application, but it creates an inventory problem: an administrator looking only for a security-labelled release or a matching CVE will not find one in the change log. The build appears as a generic maintenance release, despite now being the remediation for a CISA-published vulnerability.
There is another deployment complication. Medixant’s version-history page tells customers to sign in to their license account to obtain the version covered by their license. The public records reviewed do not spell out whether every existing 2025.2 installation is entitled to 2026.1, whether any update channel deploys it automatically, or whether the portable CD/DVD/USB package is built from the same fixed code. Organizations should verify this rather than assuming an installed copy will self-update.
The distinction matters most for managed environments. The current CISA advisory identifies the affected product as “Medixant RadiAnt DICOM,” while Medixant markets it as “RadiAnt DICOM Viewer.” Asset inventories may use either name, and some software catalogs may report the year-based version as
2025.2 while the executable metadata uses a separate build number. Search for both product names and confirm the installed application’s About dialog shows 2026.1 or later.What Windows and healthcare IT teams should do now
The priority is remediation rather than compensating controls. Replace every 2025.2-or-earlier RadiAnt installation with 2026.1, including departmental workstations that are not enrolled in central endpoint management and any portable-media viewing stations maintained outside the radiology team.A practical response should include the following actions:
- Update RadiAnt DICOM Viewer to version 2026.1 or later and record the installed version after deployment rather than treating a successful installer exit code as proof of remediation.
- Search software inventory records for both “RadiAnt DICOM,” “RadiAnt DICOM Viewer,” and Medixant, then manually check devices where the product was installed by clinicians or departmental staff.
- Treat the viewer’s CD/DVD/USB and removable-media use cases as part of the affected population until Medixant confirms the package version is fixed.
- Limit opening of unsolicited or unverified DICOM studies on production clinical workstations until the update is complete, especially studies received outside a managed PACS connection.
- Preserve suspicious DICOM samples and relevant Windows crash telemetry if RadiAnt terminates unexpectedly, rather than reopening the same file repeatedly to diagnose it.
The decisive date for administrators is July 14, 2026: that is when Medixant built RadiAnt DICOM Viewer 2026.1, the release CISA identifies as the fix. Any workstation still on 2025.2 or an earlier release remains exposed every time a user opens an untrusted JPEG-compressed DICOM study.
References
- Primary source: CISA
Published: 2026-08-06T12:00:00+00:00
Medixant RadiAnt DICOM | CISA
www.cisa.gov
- Related coverage: cisa.gov
Medixant RadiAnt DICOM Viewer | CISA
www.cisa.gov
- Related coverage: radiantviewer.com
DICOM Viewer - RadiAnt | Forum Thread | Import image other than Dicom format | June 10, 2016
DICOM viewer. RadiAnt is a simple, fast and intuitive DICOM viewer for medical images. Forum Thread. Import image other than Dicom format | June 10, 2016www.radiantviewer.com - Related coverage: radiantviewer.com
- Related coverage: nvd.nist.gov
NVD - CVE-2026-12473
nvd.nist.gov