CISA advisory ICSMA-25-224-01 lands on Santesoft Sante PACS Server, the imaging archive, versions before 4.2.3. Five CVEs. Start with CVE-2025-53948, a double free that a crafted HL7 message turns into a denial of service on the archive itself, then CVE-2025-54156, where the web portal transmits credentials in cleartext. Add path traversal and two cross-site scripting bugs and you have arbitrary file creation, cookie theft and data disclosure, top base score 7.5.

A PACS holds every image, and an attacker who can crash it or read its login traffic is inside the part of the network hospitals trust most. Chizuru Toyama of TXOne Networks reported it. Upgrade to 4.2.3, and if you ship anything that speaks HL7, treat the message parser as an attack surface, not plumbing.