As cited
Copy frozen at (site build).
vulnerabilities
Thermo Fisher Applied Biosystems Genetic Analyzers
Thermo Fisher Applied Biosystems Genetic Analyzers contain a vulnerability (CVE-2026-17583) that allows attackers to modify DNA output files without detection, potentially resulting in inaccurate test results. The vulnerability affects multiple instrument software versions across the product line due to missing integrity checks on .fsa/.hid files. Thermo Fisher has released security updates implementing digital signatures for most affected products, while three end-of-life products have no patches available.
Why it matters: Clinical laboratories and research institutions using these genetic analyzers face integrity risks to DNA test data that could affect patient diagnoses and results. Organizations must prioritize patching affected systems to version 4.0.3, 5.0.3, 1.2.6, 1.2.1, or 1.7.4 depending on their instrument model, and implement file custody controls for systems that cannot be immediately updated.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Thermo Fisher Applied Biosystems Genetic Analyzers
Thermo Fisher Applied Biosystems Genetic Analyzers contain a vulnerability (CVE-2026-17583) that allows attackers to modify DNA output files without detection, potentially resulting in inaccurate test results. The vulnerability affects multiple instrument software versions across the product line due to missing integrity checks on .fsa/.hid files. Thermo Fisher has released security updates implementing digital signatures for most affected products, while three end-of-life products have no patches available.
Why it matters: Clinical laboratories and research institutions using these genetic analyzers face integrity risks to DNA test data that could affect patient diagnoses and results. Organizations must prioritize patching affected systems to version 4.0.3, 5.0.3, 1.2.6, 1.2.1, or 1.7.4 depending on their instrument model, and implement file custody controls for systems that cannot be immediately updated.
- Source published
- First seen by Cybersecurity Tracker