INFINITT PACS System Manager, versions 3.0.11.5 BN9 and prior, got ICSMA-25-100-01. Two unrestricted file-upload flaws, CVE-2025-27714 and CVE-2025-24489, plus an information-exposure bug, CVE-2025-27721 at 7.5. Piotr Kijewski of the Shadowserver Foundation reported them.
Unrestricted upload is a direct line to code execution. Put an executable where the server will run it and the imaging archive is yours, and the info-exposure bug hands you reconnaissance to go with the foothold. A PACS holds every image, every study, every identifier a radiology department has.
Validate what gets uploaded, type and extension and content, and never store an upload where the web server will execute it. This bug class is old and it still owns servers.