Skip to content
Multiple CVEs Disclosed for MONAI with High Impact Risks

Multiple CVEs Disclosed for MONAI with High Impact Risks

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •Five critical vulnerabilities in MONAI disclosed on 2026-09-27.
  • •Vulnerabilities include remote code execution and unsafe deserialization risks.
  • •Immediate upgrades to fixed versions are essential to mitigate risks.

Five critical vulnerabilities (CVE-2026-100840, CVE-2026-100843, CVE-2026-100844, CVE-2026-100845, CVE-2026-100846) were published on 2026-09-27 for MONAI versions prior to 1.6.0. These vulnerabilities include remote code execution and unsafe deserialization risks, affecting users in medical imaging and AI research. Attack vectors involve loading malicious configuration files or data files that execute arbitrary code. The impact could lead to data theft, model tampering, and disruption of clinical workflows. No active exploitation has been confirmed, but the vulnerabilities pose significant risks due to their potential for code execution in trusted environments. Users are urged to upgrade to fixed versions and restrict untrusted inputs. The vulnerabilities were disclosed by Redpacketsecurity, emphasizing the urgency for affected teams to take action.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-100840 published
Remote code execution vulnerability in MONAI's bundle configuration engine disclosed.
Redpacketsecurity
2026-09-27
CVE-2026-100843 published
Unsafe pickle deserialization vulnerability in algo_from_pickle() function disclosed.
Redpacketsecurity
2026-09-27
CVE-2026-100844 published
OS command injection vulnerability in nnUNetV2Runner component disclosed.
Redpacketsecurity
2026-09-27
CVE-2026-100845 published
Unsafe deserialization vulnerability in NumpyReader class disclosed.
Redpacketsecurity
2026-09-27
CVE-2026-100846 published
Deserialization of untrusted data vulnerability in algo_from_pickle function disclosed.
Redpacketsecurity

More articles in this cluster (9)

Following this threat?

Track CVE-2025-23304 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed