Skip to main content
Cybersecurity

CISA Flags Exploited Vulnerabilities in Network and Imaging Tools

Federal alerts warn of active exploits against remote management and router software, alongside a high-severity flaw in medical imaging servers.

CareScope Editorial/September 13, 2026/1 min read

The short version

  • CISA added a ConnectWise ScreenConnect flaw to its list of known exploited vulnerabilities, warning that exposed systems face immediate risk of compromise.
  • MikroTik RouterOS flaws are also under active exploitation, potentially giving attackers total control over exposed networking systems.
  • A denial-of-service vulnerability in Orthanc DICOM Server (CVSS score 8.1) threatens access to medical images and diagnostic workflows.

Why it matters

Malicious cyber actors frequently target vulnerabilities in remote support tools and network routing gear, using active exploits to gain total system control. In clinical environments, software flaws also directly threaten care delivery, as shown by a high-severity denial-of-service vulnerability that can knock imaging servers offline and interrupt diagnostic workflows.

The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting ConnectWise ScreenConnect to its Known Exploited Vulnerabilities catalog. CISA reports that active exploitation of this flaw has been observed in the wild. Exposed systems face an immediate risk of compromise, and the agency encourages all organizations to prioritize patching cataloged flaws.

At the same time, CISA issued a warning regarding actively exploited vulnerabilities in MikroTik RouterOS. These vulnerabilities serve as frequent attack vectors for cyber actors. According to CISA, when present on publicly exposed networking equipment, these flaws can grant attackers total control over the affected system after exploitation.

Healthcare infrastructure also faced a direct advisory involving the Orthanc DICOM Server, an application used worldwide across healthcare and public health organizations to manage imaging data. CISA warned that the software contains a denial-of-service flaw carrying a CVSS v3 score of 8.1.

Because Orthanc manages imaging data, a denial-of-service attack against the server can disrupt diagnostic workflows and block access to medical images. CISA continues to emphasize that organizations beyond federal agencies should adopt risk-based vulnerability management to safeguard critical systems.

The CareScope take

Practice administrators should ensure their IT teams and managed service providers track and prioritize vulnerabilities highlighted by CISA. When remote access software, edge routers, or imaging servers like Orthanc are exposed, rapid patching is essential to prevent system takeovers and clinical interruptions.

Sources

  1. CISA Adds ConnectWise ScreenConnect Flaw to Exploited Vulnerabilities ListCybersecurity and Infrastructure Security Agency
  2. CISA Warns of Actively Exploited MikroTik RouterOS VulnerabilitiesCybersecurity and Infrastructure Security Agency
  3. Orthanc DICOM Server Vulnerable to Denial-of-Service FlawCybersecurity and Infrastructure Security Agency

CareScope cites primary sources — regulators, standards bodies, and published research — wherever a claim depends on them. Reporting is editorially independent and is not legal advice.

Cybersecurity · CISA · Vulnerability Management · Health IT · Diagnostic Imaging

The CareScope Briefing

A practical briefing for practice leaders.

Each week, we cover one development affecting healthcare now and one issue worth preparing for next.

Email only. No account, no sales calls, unsubscribe whenever you like.