CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Thermo Fisher Applied Biosystems Genetic Analyzers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3835

As cited

Copy frozen at (site build).

vulnerabilities

Thermo Fisher Applied Biosystems Genetic Analyzers

Thermo Fisher Applied Biosystems Genetic Analyzers contain a vulnerability (CVE-2026-17583) that allows attackers to modify DNA output files without detection, potentially resulting in inaccurate test results. The vulnerability affects multiple instrument software versions across the product line due to missing integrity checks on .fsa/.hid files. Thermo Fisher has released security updates implementing digital signatures for most affected products, while three end-of-life products have no patches available.

Why it matters: Clinical laboratories and research institutions using these genetic analyzers face integrity risks to DNA test data that could affect patient diagnoses and results. Organizations must prioritize patching affected systems to version 4.0.3, 5.0.3, 1.2.6, 1.2.1, or 1.7.4 depending on their instrument model, and implement file custody controls for systems that cannot be immediately updated.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Thermo Fisher Applied Biosystems Genetic Analyzers

Thermo Fisher Applied Biosystems Genetic Analyzers contain a vulnerability (CVE-2026-17583) that allows attackers to modify DNA output files without detection, potentially resulting in inaccurate test results. The vulnerability affects multiple instrument software versions across the product line due to missing integrity checks on .fsa/.hid files. Thermo Fisher has released security updates implementing digital signatures for most affected products, while three end-of-life products have no patches available.

Why it matters: Clinical laboratories and research institutions using these genetic analyzers face integrity risks to DNA test data that could affect patient diagnoses and results. Organizations must prioritize patching affected systems to version 4.0.3, 5.0.3, 1.2.6, 1.2.1, or 1.7.4 depending on their instrument model, and implement file custody controls for systems that cannot be immediately updated.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary