CVE-2026-58126Hyland · Pacsgear
Vulnerability data via NVD (ingested)
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58126product:"Hyland Pacsgear"http.html:"Pacsgear"More intel sources (5)
vuln:CVE-2026-58126vulnerabilities.cve_id: CVE-2026-58126CVE-2026-58126CVE-2026-58126"CVE-2026-58126" exploit -site:nvd.nist.gov