CVE-2026-58126General(hyland / pacsgear)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch hyland pacsgear systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pacsgear

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 5 classified signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-07-11); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
pacsgear

Deep dive

Activity timeline10 mentions / 7d
01223Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-10: 1Mentions · 2026-07-11: 3Mentions · 2026-07-12: 2Mentions · 2026-07-15: 1Mentions · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-02: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 107-0107-0207-1007-1107-1207-1507-17
Signal classification3 categories
General
550.0%
Disclosure
440.0%
PoC
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-021
PoC1
2026-07-101
General1
2026-07-113
Disclosure2General1
2026-07-122
General2
2026-07-151
General1
2026-07-171
Disclosure1
Full discourse10 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-58126 PACSgear PACS Scan 5.2.1に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/09/cve-2026-58126-pacsgear-pacs-scan-521/ #IT #Security #cybersecurity

    Post summary

    An urgent notice alerts that PACSgear PACS Scan 5.2.1 suffers from a severe vulnerability (CVE‑2026‑58126) and calls for immediate action, but offers no technical details or evidence of exploitation.

    0001041
    207 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-58126 PACSgear PACS Scan 5.2.1に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/09/cve-2026-58126-pacsgear-pacs-scan-521/ #IT #Security #cybersecurity

    Post summary

    The post alerts to a serious vulnerability (CVE-2026-58126) in PACSgear PACS Scan 5.2.1 and urges immediate action, but provides no technical details, PoC, or patch information.

    0100064
    207 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Hyland Software Inc.のPACSgearにおける複数の脆弱性(CVE-2026-58126)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The tweet introduces a discussion of CVE‑2026‑58126 but provides no technical details, exploit evidence, or mitigation information.

    0000082
    840 followersView on X
  • ゆぅさん@YY20424277
    General

    もし自分の現場で「Hyland Software Inc.のPACSgearにおける複数の脆弱性(CVE-2026-58126)」が起きたら、最初の一手は何ですか? →背景/目的/効果の3軸でfirst-stepを整理しました。 #セキュリティ #インシデント対応 ▶ 無料トレーニング: https://www.intect-i.jp/training/free/?utm_source=sns&utm_medium=social&utm_campaign=free_training

    Post summary

    The post only poses a general incident‑response question about CVE-2026-58126, lacking specific technical, exploit, or patch information.

    0000078
    840 followersView on X
  • ゆぅさん@YY20424277
    General

    「Hyland Software Inc.のPACSgearにおける複数の脆弱性(CVE-2026-58126)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The post references a CVE but offers no additional details, PoC, exploit, or mitigation information.

    0000079
    840 followersView on X
  • ゆぅさん@YY20424277
    Disclosure

    【3軸解説】「Hyland Software Inc.のPACSgearにおける複数の脆弱性(CVE-2026-58126)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post introduces an article that analyzes Hyland’s PACSgear vulnerability (CVE‑2026‑58126) by outlining its background, purpose, and effect, but it does not provide technical details, PoC, or exploitation evidence.

    0000069
    840 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-58126 PACSgear PACS Scan 5.2.1に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/09/cve-2026-58126-pacsgear-pacs-scan-521/ #IT #Security #cybersecurity

    Post summary

    The post alerts to a severe vulnerability (CVE‑2026‑58126) in PACSgear PACS Scan 5.2.1 and urges immediate action, but offers no further technical detail, PoC, or patch information.

    0000048
    206 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-58126 PACSgear PACS Scan 5.2.1に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/09/cve-2026-58126-pacsgear-pacs-scan-521/ #IT #Security #cybersecurity

    Post summary

    Urgent notice that CVE-2026-58126 affects PACSgear PACS Scan 5.2.1, highlighting the need for immediate action, but no further technical details or remedial steps are provided.

    0000046
    206 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    PoC

    CVE-2026-58126 Hyland PACSgear PACS Scan Unauthenticated remoting could allow file read/write and remote code execution through a DLL-hijacking chain Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-01/TIER_2_CVE-2026-58126.md #CyberSecurity #HealthcareCybersecurity #VulnerabilityManagement

    Post summary

    The post announces CVE-2026-58126 with technical details and references a GitHub analysis that likely contains a proof‑of‑concept. No exploitation, patch, or active usage claims are made.

    0000041
    56 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated .NET Remoting RCE in PACSgear PACS Scan (CVE-2026-58126) PACSgear PACS Scan 5.2.1 exposes a .NET Remoting TCP service on port 22222 used by PGImageExchQueue.exe that allows unauthenticated arbitrary file read/write. The root issue is insecure exposed remoting endpoints and improper authentication/access control, enabling arbitrary file operations that can be chained into code execution. An attacker can reach the service remotely with no credentials, write a malicious DLL into the application directory, and trigger DLL hijacking in PGImageExchangeQueueSvc.exe (e.g., CRYPTSP.DLL) after forcing or waiting for a service restart. Successful exploitation yields full remote code execution as NT AUTHORITY\SYSTEM and can enable complete host takeover, lateral movement, and data theft in clinical imaging environments. 👉 Affected: PACSgear PACS Scan 5.2.1 | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces a critical unauthenticated RCE in PACSgear PACS Scan, detailing the attack vector and impact, but no PoC, exploit tool, or active exploitation evidence. The patch status is noted as pending, underscoring the need for mitigation.

    0000080
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphylandpacsgear---

Explore more