PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41085 Thermo Fisher Scientific CVE debrief

Thermo Fisher Scientific Torrent Suite Dx through version 5.14.2 contains a privilege escalation vulnerability (CWE-269) that allows an authenticated user with limited privileges to gain unauthorized administrator-level access by exploiting specific system interfaces. The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH severity) with network attack vector, low attack complexity, and low privileges required. Published to the NVD on May 18, 2026, this issue affects diagnostic software used in genetic sequencing workflows. The vulnerability status remains 'Awaiting Analysis' per NVD records. Organizations using affected versions should restrict network access to administrative interfaces and monitor for privilege escalation attempts pending vendor remediation guidance.

Vendor
Thermo Fisher Scientific
Product
Torrent Suite Dx
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-18
Original CVE updated
2026-05-18
Advisory published
2026-05-18
Advisory updated
2026-05-18

Who should care

Healthcare organizations operating Thermo Fisher Scientific genetic sequencing instruments, clinical laboratories using Torrent Suite Dx for diagnostic workflows, biomedical research facilities, and security teams responsible for medical device cybersecurity compliance.

Technical summary

The vulnerability exists in the access control implementation of Torrent Suite Dx software versions through 5.14.2. Authenticated users with restricted privileges can leverage specific system interfaces to elevate their permissions to administrator level. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates this is network-exploitable with low complexity, requiring only low-level privileges and no user interaction, resulting in high impact across confidentiality, integrity, and availability dimensions. The weakness is classified under CWE-269 (Improper Privilege Management).

Defensive priority

HIGH

Recommended defensive actions

  • Restrict network access to Torrent Suite Dx administrative interfaces to trusted hosts only
  • Audit existing user accounts with limited privileges for anomalous privilege escalation attempts
  • Monitor system logs for unauthorized access to administrative functions
  • Contact Thermo Fisher Scientific support to confirm affected versions and obtain remediation timeline
  • Apply vendor patches when available, prioritizing systems with external network exposure

Evidence notes

CVE description confirms privilege escalation through specific system interfaces. CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network-exploitable with significant confidentiality, integrity, and availability impact. NVD status 'Awaiting Analysis' suggests full technical details pending. Vendor attribution based on reference domain thermofisher.com with low confidence requiring review.

Official resources

2026-05-18