Philips published or updated four advisories between early June and July 30. A Trellix breach response (no Philips products known impacted). The OFFIS DCMTK vulnerabilities. Windows kernel CVE-2026-45657 across Holter, IntelliSpace ECG, ST80i and PIC iX. And the Defender findings, BlueHammer, RedSun and UnDefend, touching IntelliVue and UroNav.

None of it is Philips code. A monitoring platform inherits the Windows kernel. An ECG cart inherits Defender. Every imaging product inherits DICOM toolkits. Now device makers inherit their security vendors’ breaches too.

The kernel RCE reaching PIC iX 4.x is the one to watch. A patient information center is the box a hospital never wants to reboot. Which is exactly where patch lag runs longest.

This is what working PSIRT output looks like. Fast, specific, honest about not-impacted. Forty plus large manufacturers publish nothing at all. That gap is the real story.