1. CISA ICS Medical Advisory — OFFIS DCMTK Toolkit
CISA published ICSMA-26-181-01 on 30 June 2026, disclosing five vulnerabilities in OFFIS DCMTK (DICOM Toolkit), an open-source library widely embedded in medical imaging systems, PACS, and DICOM-handling components across the device industry.
Affected product: OFFIS DCMTK versions prior to 3.7.0.
Severity: One critical flaw, CVE-2026-50003 (CVSS 9.8), permitting arbitrary file writes; four additional high-severity flaws (CVE-2026-52868, CVE-2026-50254, CVE-2026-35505, CVE-2026-44628, CVSS 7.5–8.2) enabling unauthorized information access, memory exhaustion, or process crashes.
Fix: Upgrade to DCMTK 3.7.1 or later.
This is the third DICOM-ecosystem library flagged by CISA in the past two weeks (following pydicom/pynetdicom and OHIF Viewers, reported 25 June). Manufacturers with DCMTK in their software bill of materials — directly or via imaging/PACS suppliers — should confirm version status and patch promptly; this pattern indicates DICOM tooling is receiving sustained researcher and adversary attention.
Source: ICSMA-26-181-01 — CISA
2. EU Cyber Resilience Act — Reporting Platform Still Not Operational
With the 11 September 2026 reporting deadline under 75 days away, ENISA’s Single Reporting Platform (SRP) — the mandatory single entry point for Article 14 vulnerability and incident notifications — remained non-operational as of 29 June 2026. ENISA has committed to publishing access, registration, training, and dry-run materials “during June 2026,” with the platform itself scheduled to go live by the 11 September start date, alongside a pre-launch testing window.
The 24-hour early-warning, 72-hour notification, and 14-day final-report clocks all run from the moment a manufacturer becomes aware of an actively exploited vulnerability or severe incident — not from when the platform becomes available. As previously reported, medical devices under MDR/IVDR are formally exempt from CRA product requirements, but manufacturers remain exposed indirectly through third-party software components that are in scope.
Action items: identify the designated national CSIRT for your EU establishment (or authorized representative); stand up an internal detection/triage process capable of meeting the 24/72-hour/14-day rhythm; and watch for ENISA’s onboarding materials so registration and a dry run are complete before a live incident forces a first attempt.
Source: With Reporting Due on 11 September 2026, ENISA’s Single Reporting Platform Is Still Not Live — cyberresilienceact.eu
3. Standards Spotlight — ISO/IEC 27090 (AI Cybersecurity) Reaches FDIS Stage
ISO/IEC FDIS 27090, “Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and failures in artificial intelligence systems,” entered its Final Draft International Standard ballot on 23 June 2026; voting closes 18 August 2026, with publication expected in the second half of 2026.
Scope: guidance addressing five AI-specific threat categories — data poisoning, evasion attacks, model extraction, membership inference, and prompt injection.
Status: informative rather than normative (no “shall” requirements); organizations cannot be certified against it in isolation, unlike ISO/IEC 27001 or 42001.
Relevance to manufacturers: as AI/ML-enabled functionality becomes more common in SaMD and connected devices, ISO/IEC 27090 is positioned as a complement to IEC 81001-5-1 and ISO/IEC 27001 — addressing AI-specific attack surfaces that neither standard currently covers. Manufacturers building AI-enabled products should track the FDIS ballot outcome and begin mapping its threat categories into existing threat-modeling and risk-management processes ahead of formal publication.
Source: ISO/IEC FDIS 27090 — ISO
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.