Illumina manufactures a focused portfolio of next-generation sequencing instruments—including the iSeq, MiSeq, MiSeq, NextSeq, and related platforms—widely deployed in genomics research and clinical diagnostic laboratories. Vulnerabilities affecting these systems skew strongly toward critical severity and concentrate in privilege-escalation, access-control, and information-disclosure weakness classes that reflect the networked, multi-tenant nature of laboratory instrumentation. Defenders should prioritize inventory and network isolation of affected instruments, particularly in clinical environments where sequencing data carries regulatory and patient-privacy obligations; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Illumina over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1517CRITICAL LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change setti | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-1519CRITICAL LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remot | Jun 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-1966CRITICAL Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor could upload and execute code rem | Apr 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-1518CRITICAL LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure. | Jun 24, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-1968HIGH
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on al | Apr 28, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-1521CRITICAL LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data. | Jun 24, 2022 | 9.1 | 22 | NO | NO |
CVE-2022-1524MEDIUM LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials. | Jun 24, 2022 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Illumina.
Media articles that mention a CVE ID that affects a product developed by Illumina — matched by CVE ID, not by vendor name.