🔐 CVE Alert

CVE-2026-17583

HIGH 8.4

Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

CWE CWE-353
Vendor thermo fisher
Product applied biosystems 3500/3500xl series data collection software
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for thermo fisher applied biosystems 3500/3500xl series data collection software

Be the first to know when new high vulnerabilities affecting thermo fisher applied biosystems 3500/3500xl series data collection software are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Thermo Fisher / Applied Biosystems 3500/3500xL Series Data Collection Software
0 ≤ 4.0.2
Thermo Fisher / Applied Biosystems 3730/3730xL Series Data Collection Software
0 ≤ 5.0.2
Thermo Fisher / Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software
0 ≤ 1.2.5
Thermo Fisher / Applied Biosystems SeqStudio Flex Series Instrument Software
0 ≤ 1.2.0
Thermo Fisher / Applied Biosystems GeneMapper ID-X Software
0 ≤ 1.7.3
Thermo Fisher / Applied Biosystems 3130 Series Data Collection Software
0 ≤ 4.1
Thermo Fisher / ABI PRISM 3100/3100-Avant Data Collection Software
0 ≤ 2.0
Thermo Fisher / ABI PRISM 310 Data Collection Software
0 ≤ 3.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
documents.thermofisher.com: https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf cisa.gov: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-17583

Credits

Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA.