PatchSiren cyber security CVE debrief
CVE-2026-41085 Thermo Fisher Scientific CVE debrief
Thermo Fisher Scientific Torrent Suite Dx through version 5.14.2 contains a privilege escalation vulnerability (CWE-269) that allows an authenticated user with limited privileges to gain unauthorized administrator-level access by exploiting specific system interfaces. The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH severity) with network attack vector, low attack complexity, and low privileges required. Published to the NVD on May 18, 2026, this issue affects diagnostic software used in genetic sequencing workflows. The vulnerability status remains 'Awaiting Analysis' per NVD records. Organizations using affected versions should restrict network access to administrative interfaces and monitor for privilege escalation attempts pending vendor remediation guidance.
- Vendor
- Thermo Fisher Scientific
- Product
- Torrent Suite Dx
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-18
Who should care
Healthcare organizations operating Thermo Fisher Scientific genetic sequencing instruments, clinical laboratories using Torrent Suite Dx for diagnostic workflows, biomedical research facilities, and security teams responsible for medical device cybersecurity compliance.
Technical summary
The vulnerability exists in the access control implementation of Torrent Suite Dx software versions through 5.14.2. Authenticated users with restricted privileges can leverage specific system interfaces to elevate their permissions to administrator level. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates this is network-exploitable with low complexity, requiring only low-level privileges and no user interaction, resulting in high impact across confidentiality, integrity, and availability dimensions. The weakness is classified under CWE-269 (Improper Privilege Management).
Defensive priority
HIGH
Recommended defensive actions
- Restrict network access to Torrent Suite Dx administrative interfaces to trusted hosts only
- Audit existing user accounts with limited privileges for anomalous privilege escalation attempts
- Monitor system logs for unauthorized access to administrative functions
- Contact Thermo Fisher Scientific support to confirm affected versions and obtain remediation timeline
- Apply vendor patches when available, prioritizing systems with external network exposure
Evidence notes
CVE description confirms privilege escalation through specific system interfaces. CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates network-exploitable with significant confidentiality, integrity, and availability impact. NVD status 'Awaiting Analysis' suggests full technical details pending. Vendor attribution based on reference domain thermofisher.com with low confidence requiring review.
Official resources
2026-05-18