Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    The Goat's Weekly

    Medical Device Cybersecurity News: Week of Monday, July 6, 2026

    The medical imaging sector faces a concentrated wave of vulnerabilities within critical DICOM communication libraries and viewers.

    Hero image for Medical Device Cybersecurity News: Week of Monday, July 6, 2026
    Week of July 6, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    4 min read876 words

    Key Takeaways

    • Multiple vulnerabilities in the OFFIS DCMTK toolkit allow for file restriction bypasses and system crashes via memory exhaustion.
    • A Server-Side Request Forgery (SSRF) flaw in OHIF Viewers permits attackers to hijack active user sessions.
    • The pynetdicom library contains a path traversal vulnerability that could allow unauthenticated remote attackers to overwrite critical system data.
    • Manufacturers of Class II and III diagnostic devices using Python-based DICOM stacks face the highest risk of exploitation.
    • Security teams must update OHIF Viewers to version 3.12.1 and pynetdicom to version 3.0.4 immediately.
    • Documented patching or compensating controls for these libraries will be expected in upcoming regulatory filings.

    The medical imaging sector faces a concentrated wave of vulnerabilities within critical DICOM communication libraries and viewers. Security teams must address high-impact flaws in OFFIS DCMTK, OHIF Viewers, and the pynetdicom library to prevent remote exploitation and unauthorized data overwrites.

    Risk management for imaging devices takes center stage this week as three separate vulnerabilities affect the underlying protocols used for transmitting and viewing medical images. These flaws range from memory exhaustion and path traversal to session hijacking, impacting everything from Python-based communication stacks to web-based diagnostic workflows.

    For regulatory and security leads, these updates represent more than just technical patches. They are direct indicators of the types of software bill of materials (SBOM) components that the FDA will scrutinize during premarket submissions and postmarket surveillance audits.

    In this brief

    Why This Matters

    These vulnerabilities target the foundational blocks of medical imaging data exchange. If exploited, they can lead to unauthorized access to patient data, system instability, or the corruption of critical diagnostic information, directly impacting patient safety and clinical workflows.

    OFFIS DCMTK Toolkit Memory and Restriction Vulnerabilities

    Critical

    The OFFIS DCMTK Toolkit has been identified as having vulnerabilities that allow attackers to bypass file restrictions or cause system crashes through memory exhaustion.

    Session Hijacking via OHIF Viewers SSRF

    High

    A Server-Side Request Forgery (SSRF) vulnerability has been discovered in OHIF Viewers.

    Path Traversal in pynetdicom Library

    Critical

    The pydicom pynetdicom library contains a critical path traversal flaw.

    ## What to do this week * Conduct an SBOM audit to identify every device and system currently utilizing DCMTK, OHIF Viewers, or pynetdicom. * Schedule emergency patch windows for any systems running pynetdicom versions earlier than 3.0.4 or OHIF Viewers below 3.12.1. * Review regulatory submission timelines to ensure that documentation regarding these DICOM library patches is included in upcoming FDA filings.

    How Blue Goat Cyber Helps

    Blue Goat Cyber provides specialized medical device security services to help manufacturers identify and mitigate vulnerabilities in their software supply chain. Our team, led by Christian Espinosa, assists with penetration testing and regulatory alignment to ensure your devices meet current safety standards. Visit our services page to learn how we support SBOM management and vulnerability disclosure.

    FAQ

    Get the next issue

    Subscribe to stay informed on the latest medical device security threats at /news/the-goats-weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.