Genetic analyzers used in labs around the world write out DNA result files that can be edited after the fact, with nothing in the software to show they were changed, CISA warned on 4 August 2026.
The advisory covers a long list of Thermo Fisher Applied Biosystems instruments and the software that drives them. It is not a break-in bug. It is an omission: the .fsa and .hid files the machines produce carry no integrity protection, so an altered file is indistinguishable from an original. CISA tracks the issue as CVE-2026-17583 and rates it 8.4 (high) on CVSS 3.1, under the weakness class "missing support for integrity check". Successful exploitation, CISA says, could let an attacker modify those output files, "tampering with DNA data and resulting in inaccurate test results".
What's affected
Eight product lines are listed as vulnerable: Applied Biosystems 3500/3500xL Data Collection Software up to 4.0.2, 3730/3730xL Data Collection Software up to 5.0.2, SeqStudio Genetic Analyzer Data Collection Software up to 1.2.5, SeqStudio Flex Series Instrument Software up to 1.2.0, GeneMapper ID-X up to 1.7.3, 3130 Series Data Collection Software up to 4.1, and the older ABI PRISM 3100/3100-Avant (up to 2.0) and ABI PRISM 310 (up to 3.1). CISA files the advisory under the Healthcare and Public Health sector and says the equipment is deployed worldwide.
Why it matters
The attack is local, not remote. CISA's severity vector marks the vulnerability as not exploitable over a network, which means somebody needs access to the machine or to the files it writes. That narrows the threat to insiders and to anyone who has already gained a foothold on a lab workstation, but it does not make it academic: the entire value of a sequencing run is that the file at the end can be trusted, and Thermo Fisher's own mitigation advice tells labs to maintain a secure chain of custody for files generated by the instrumentation throughout the analysis workflow. CISA says no public exploitation specifically targeting this vulnerability has been reported to it so far.
What you should do
Thermo Fisher has shipped updates that add digital signatures to the instrument software, so users can verify that a data file has not been modified. The fixed versions are 4.0.3 for the 3500/3500xL line, 5.0.3 for the 3730/3730xL line, 1.2.6 for SeqStudio, 1.2.1 for SeqStudio Flex and 1.7.4 for GeneMapper ID-X. Three older products get nothing: the 3130 Series, the ABI PRISM 3100/3100-Avant and the ABI PRISM 310 are all end of life, and the vendor states no update will be provided. Labs still running those will have to rely on process rather than software. Until the updates are installed, Thermo Fisher recommends storing generated files on encrypted, password-protected media, restricting access to authorized personnel, applying least privilege on the systems that run the instruments and the downstream analysis software, and using firewall rules and network access control lists to limit internet connectivity to trusted sources.
The vulnerability was reported to CISA by Nathaniel Adams, Laura Gaydosh-Combs and Kevin Dyer. The full product and remediation list is in CISA's advisory ICSMA-26-216-01, and Thermo Fisher's own security bulletin carries the vendor's guidance. IntelFusions has covered several comparable integrity and access failures in operational technology in recent weeks, including fuel terminal controllers shipping with an open root debug port and attackers locking water utilities out of internet-facing PLCs.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.