Redpacketsecurity Multiple CVEs Disclosed for MONAI with High Impact Risks
Article Content
- •Five critical vulnerabilities in MONAI disclosed on 2026-09-27.
- •Vulnerabilities include remote code execution and unsafe deserialization risks.
- •Immediate upgrades to fixed versions are essential to mitigate risks.
Five critical vulnerabilities (CVE-2026-100840, CVE-2026-100843, CVE-2026-100844, CVE-2026-100845, CVE-2026-100846) were published on 2026-09-27 for MONAI versions prior to 1.6.0. These vulnerabilities include remote code execution and unsafe deserialization risks, affecting users in medical imaging and AI research. Attack vectors involve loading malicious configuration files or data files that execute arbitrary code. The impact could lead to data theft, model tampering, and disruption of clinical workflows. No active exploitation has been confirmed, but the vulnerabilities pose significant risks due to their potential for code execution in trusted environments. Users are urged to upgrade to fixed versions and restrict untrusted inputs. The vulnerabilities were disclosed by Redpacketsecurity, emphasizing the urgency for affected teams to take action.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track CVE-2025-23304 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has…