Critical

Thermo Fisher Applied Biosystems Genetic Analyzers

All CISA Advisories

Overview

A serious vulnerability has been identified in several Thermo Fisher Applied Biosystems Genetic Analyzers, which could allow attackers to tamper with DNA data by modifying output files. This flaw affects multiple versions of their software, including the 3500 Series, 3730 Series, SeqStudio, and GeneMapper ID-X, among others. The risk is significant because altered DNA test results could lead to incorrect diagnoses and treatments in healthcare settings. To mitigate the issue, Thermo Fisher has released security updates that implement digital signatures to ensure data integrity. Users are advised to update their software to the latest versions as soon as possible and to follow interim measures to secure their data until the updates can be applied.

Key Takeaways

  • Affected Systems: Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2, Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2, SeqStudio Genetic Analyzer Data Collection Software <=1.2.5, SeqStudio Flex Series Instrument Software <=1.2.0, GeneMapper ID-X Software <=v1.7.3, 3130 Series Data Collection Software <=4.1, ABI PRISM 3100/3100-Avant Data Collection Software <=2.0, ABI PRISM 310 Data Collection Software <=3.1.
  • Action Required: Thermo Fisher has provided security updates: Applied Biosystems 3500/3500xL Series Data Collection Software update to version 4.
  • Timeline: Disclosed on 2026-08-04

Original Article Summary

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5 Applied Biosystems SeqStudio Flex Series Instrument Software <=1.2.0 Applied Biosystems GeneMapper ID-X Software <=v1.7.3 Applied Biosystems 3130 Series Data Collection Software <=4.1 ABI PRISM 3100/3100-Avant Data Collection Software <=2.0 ABI PRISM 310 Data Collection Software <=3.1 CVSS Vendor Equipment Vulnerabilities v3 8.4 Thermo Fisher Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-17583 The affected product is vulnerable because its .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. View CVE Details Affected Products Thermo Fisher Applied Biosystems Genetic Analyzers Vendor: Thermo Fisher Product Version: Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software: <=4.0.2, Thermo Fisher Applied Biosystems 3730/3730xL Series Data Collection Software: <=5.0.2, Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: <=1.2.5, Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software: <=1.2.0, Thermo Fisher Applied Biosystems GeneMapper ID-X Software: <=v1.7.3, Thermo Fisher Applied Biosystems 3130 Series Data Collection Software: <=4.1, Thermo Fisher ABI PRISM 3100/3100-Avant Data Collection Software: <=2.0, Thermo Fisher ABI PRISM 310 Data Collection Software: <=3.1 Product Status: known_affected Remediations Mitigation Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified. Vendor fix Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3 https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe Vendor fix Applied Biosystems 3730/3730xL Series Data Collection Software: Update to version 5.0.3 https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe Vendor fix Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: Update to version 1.2.6 https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg Vendor fix Applied Biosystems SeqStudio Flex Series Instrument Software: Update to version 1.2.1 https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg Vendor fix Applied Biosystems GeneMapper ID-X Software: Update to version 1.7.4 https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe Vendor fix Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided Vendor fix ABI PRISM 3100/3100-Avant Data Collection Software: Product is End of Life (EoL), no update provided Vendor fix ABI PRISM 310 Data Collection Software: Product is End of Life (EoL), no update provided Mitigation For users who are unable to immediately implement all applicable security updates, Thermo Fisher Scientific recommends implementing the following interim mitigation measures until the applicable updates have been installed: -Maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow. -Store generated files on encrypted, password-protected storage media (for example, encrypted USB drives or encrypted hard drives). -Restrict access to generated files to authorized personnel in accordance with your laboratory's access control policies. -Apply the principle of least privilege by limiting user permissions on systems operating the HID instrumentation or hosting associated data analysis and secondary analysis software. -Leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources. Mitigation For more information, refer to Thermo Fisher's security bulletin. https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf Relevant CWE: CWE-353 Missing Support for Integrity Check Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.2 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N Acknowledgments Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-08-04 Date Revision Summary 2026-08-04 1 Initial Publication Legal Notice and Terms of Use

Impact

Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2, Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2, SeqStudio Genetic Analyzer Data Collection Software <=1.2.5, SeqStudio Flex Series Instrument Software <=1.2.0, GeneMapper ID-X Software <=v1.7.3, 3130 Series Data Collection Software <=4.1, ABI PRISM 3100/3100-Avant Data Collection Software <=2.0, ABI PRISM 310 Data Collection Software <=3.1.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on 2026-08-04

Remediation

Thermo Fisher has provided security updates: Applied Biosystems 3500/3500xL Series Data Collection Software update to version 4.0.3, 3730/3730xL Series update to version 5.0.3, SeqStudio update to version 1.2.6, SeqStudio Flex update to version 1.2.1, GeneMapper ID-X update to version 1.7.4. For users unable to update immediately, interim measures include maintaining secure file custody, using encrypted storage, restricting access to authorized personnel, limiting user permissions, and applying firewall rules to restrict internet connectivity.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Update, and 1 more.

Related Coverage

Dem senators criticize Trump administration decisionmaking on AI security risks

CyberScoop

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Aug 4, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

BleepingComputer

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Aug 4, 2026

Prolific ransomware group behind SonicWall zero-day attacks

CyberScoop

The INC ransomware group has been linked to recent attacks exploiting zero-day vulnerabilities in SonicWall products. While they weren't the first to take advantage of these flaws, their aggressive tactics in combining both vulnerabilities have made them particularly effective at stealing and encrypting sensitive data for ransom. This situation poses a significant risk for organizations using affected SonicWall devices, as it can lead to severe data breaches and financial losses. Users and companies relying on SonicWall's security products need to be vigilant and implement necessary precautions to protect their systems. The ongoing threat from INC highlights the importance of timely updates and monitoring for unusual activity in network environments.

Aug 4, 2026

WhatsApp Scam Hijacks Accounts via Linked Devices Feature

Infosecurity Magazine

A recent WhatsApp scam has exploited the app's Linked Devices feature to take control of user accounts without needing to steal passwords. This method allows attackers to gain access to someone's WhatsApp by tricking them into providing a verification code. Victims are often misled into thinking they are verifying their own devices, making it easier for scammers to hijack accounts. This incident raises significant concerns about the security of user accounts on popular messaging platforms, especially as more people rely on these apps for personal and professional communication. Users should be cautious and verify any unexpected requests for verification codes to protect their accounts.

Aug 4, 2026

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

SecurityWeek

Researchers have found that built-in email chatbots could be weaponized by attackers to impersonate trusted employees, potentially leading to account hijacking and financial fraud. These AI assistants, often designed to make email communication more efficient, can be exploited to bypass security measures and compromise executive accounts. This poses a significant risk to organizations, as attackers could manipulate these tools to send deceptive messages that appear legitimate to recipients. The implications are serious, as companies may face not only financial losses but also damage to their reputations. Users and organizations need to be aware of these vulnerabilities and take steps to secure their email systems against such tactics.

Aug 4, 2026

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

The Hacker News

A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.

Aug 4, 2026