Eppendorf and CISA disclosed a critical vulnerability in all versions of the BioFlo 320 bioreactor that could let a remote attacker with network access take full control of the system’s user interface and associated functions and data. The issue, tracked as CVE-2026-7251 and mapped to CWE-259, carries a CVSS 9.8 rating and stems from a VNC-based remote management component that uses a hard-coded password; CISA also warned that the VNC traffic is not encrypted, increasing risk where remote access is enabled.
The BioFlo 320 is used in laboratory and healthcare environments, raising concerns that unauthorized access could allow manipulation of sensitive biochemical processes. Eppendorf released Version 5.0 to disable the vulnerable remote control protocol and urged administrators to apply the update immediately, while also confirming the affected remote feature was disabled by default and could only be enabled manually at the physical workstation tower. CISA said BIO-ISAC reported the flaw and that it had no evidence of public exploitation at the time of publication; defenders were also advised to verify local role-based protections so only trusted supervisors can change configurations.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Eppendorf released a software update, Version 5.0, that disables the vulnerable remote control protocol in the BioFlo 320. Researchers said the flaw, tracked as CVE-2026-7251, could allow unauthenticated administrative access via the VNC-based remote management component if the feature had been enabled.
On 2026-05-26, CISA published advisory ICSMA-26-146-01 for a critical vulnerability affecting all versions of the Eppendorf BioFlo 320 Bioreactor. The advisory said the VNC server uses a hard-coded password, enabling a remote attacker with network access to gain full control, and noted there were no reports of public exploitation at that time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.