PatchSiren cyber security CVE debrief
CVE-2026-44628 OFFIS DICOM CVE debrief
The OFFIS DCMTK Toolkit is affected by a vulnerability that allows an unauthenticated attacker to crash the worklist server with a single crafted query. The vulnerability exists when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This issue is related to the unauthenticated query functionality. Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Vendor
- OFFIS DICOM
- Product
- DCMTK
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-06-30
Who should care
Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Finally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operators, platforms, and security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Furthermore, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The vulnerability management process should be reviewed to ensure that all affected systems are identified and prioritized for patching. Asset inventory should also be reviewed to ensure that all affected systems are accounted for. Security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Additionally, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The affected product or component is OFFIS DCMTK Toolkit. The vulnerability class is related to unaut
Technical summary
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This can be done by reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The vulnerability affects OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts.
Defensive priority
Organizations using OFFIS DCMTK Toolkit should prioritize patching to prevent potential crashes of the worklist server.
Recommended defensive actions
- Apply the latest fix from the GitHub release once it becomes available.
- Download and implement the latest GitHub release.
- Verify the Called AE Title / storage directory and lockfile configurations.
- Monitor worklist server logs for potential crafted queries.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The source item from CISA CSAF provides details on the vulnerability, including the description and affected products. However, further information is limited, and additional verification is recommended. Organizations should verify the Called AE Title / storage directory and lockfile configurations. They should also monitor worklist server logs for potential crafted queries and review compensating controls for exposed systems while remediation is scheduled and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44628 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44628
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44628 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44628
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-181-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.