DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-26142PUBLISHED: 2026-06-09
CRITICALCVE-2026-26142

Nuance PowerScribe Deserialization RCE (Healthcare Critical Infrastructure)

VENDOR: Microsoft / Nuance//PRODUCT: Nuance PowerScribe (PowerScribe One and PowerScribe 360 Reporting)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

Deserialization of untrusted data (CWE-502) in Nuance PowerScribe, the dominant radiology dictation and reporting platform, allows an unauthenticated attacker to execute arbitrary code over the network with no credentials or user interaction required. Patches ship via the Nuance support portal — not Windows Update — making detection of unpatched systems in healthcare environments particularly difficult. Exploitation risk is high given direct connectivity to PACS and clinical imaging stacks.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSPowerScribe One 2019.1–2019.10, 2023.1 prior to SP3 Patch 6 (build 2023.3.9072) and SP2 Patch 11 (build 2023.2.3054); PowerScribe 360 Reporting versions 4.0–4.0.9
  • https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-26142
  • https://ap7i.com/posts/microsoft-june-2026-patch-tuesday/
  • https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/
  • https://blog.talosintelligence.com/microsoft-patch-tuesday-for-june-2026-snort-rules-and-prominent-vulnerabilities/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn