Government Advisory

Security Flaw Found in Thermo Fisher Genetic Analyzer Software Could Allow DNA Data Tampering

CISA · 4 Aug 2026
Key Takeaway If your business relies on lab, medical, or scientific equipment software, check with your vendor for security updates and apply them as soon as they're available.

A newly disclosed vulnerability affecting Thermo Fisher's Applied Biosystems Genetic Analyzer product line could allow attackers to tamper with .fsa and .hid output files, which store critical DNA analysis data. The flaw, rated 8.4 out of 10 on the CVSS severity scale, stems from missing protections that should prevent unauthorised modification of these files.

The vulnerability affects multiple software versions across Thermo Fisher's genetic analyzer range, including the 3500/3500xL, 3730/3730xL, SeqStudio, GeneMapper ID-X, 3130 Series, and older ABI PRISM systems. Because these instruments are used in medical, research, and forensic laboratories, tampered data could result in inaccurate test results with serious downstream consequences for patient care, scientific research, or legal proceedings.

While this issue primarily affects laboratories and healthcare organisations rather than typical small businesses, it's a useful reminder for any organisation relying on specialised scientific or medical equipment: outdated software controlling critical data can be exploited if not properly secured and updated. Businesses using or partnering with labs that operate this equipment should confirm patches are applied promptly.

ICS security healthcare technology data integrity vulnerability disclosure CISA advisory

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.