Critical Flaw in Thermo Fisher DNA Software Puts Decades of Forensic Data at Risk
A significant vulnerability, tracked as **CVE-2026-17583**, has been identified and patched in select **Applied Biosystems** human identification software from **Thermo Fisher Scientific**. This flaw could allow undetectable alteration of DNA data files, raising concerns about the integrity of forensic evidence spanning decades. While no exploitation has been reported, the implications for legal and scientific communities are substantial.
### Undetectable Tampering Possible in DNA Analysis Files
**Thermo Fisher Scientific** has released patches for a critical vulnerability (**CVE-2026-17583**) in its **Applied Biosystems** human identification software. The flaw, rated High with a **CVSS v4.0** score of 8.2, could permit nearly undetectable modifications to .fsa and .hid data files before they are loaded into analysis software.

The vendor's July 31 security bulletin details how circumvention of laboratory controls could enable these alterations. The updates introduce digital signatures to help customers verify data file integrity going forward.
### Coordinated Disclosure and Potential Impact
The vulnerability was identified by **Nathan Adams**, **Kevin Dyer**, and **Laura Gaydosh Combs**, in collaboration with the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**. **Thermo Fisher** has urged customers to install the applicable updates immediately. For those unable to update or using third-party analysis platforms, the company recommends stringent controls over file custody, storage, access, privilege, and network connectivity.
While **Thermo Fisher** has stated to The Wall Street Journal that it knows of no instances where the vulnerability has been exploited, the potential for historical data compromise is a significant concern. Researchers believe the flaw may have existed in digital files produced by crime-lab machines since 1995, and a method to detect prior tampering has not yet been found.
### Demonstration of Vulnerability
**Nathan Adams**, a systems engineer at **Forensic Bioinformatics**, demonstrated the vulnerability's ease of exploitation. Using **Anthropic's Claude**, he successfully modified a public dataset, combining scans from two individual DNA profiles into a new file that appeared untouched since 2015. This manipulated file raised no warnings in standard analysis software used by many laboratories.
Exploitation would require an attacker to gain local or remote access to a laboratory's servers and possess sufficient knowledge of DNA testing methodologies.
### Affected Products and Remediation
The updates apply to five **Applied Biosystems** human identification product lines:
* **3500/3500xL Series Data Collection Software** 4.0.2 and earlier, fixed in 4.0.3
* **3730/3730xL Series Data Collection Software** 5.0.2 and earlier, fixed in 5.0.3
* **SeqStudio Genetic Analyzer Data Collection Software** 1.2.5 and earlier, fixed in 1.2.6
* **SeqStudio Flex Series Instrument Software** 1.2.0 and earlier, fixed in 1.2.1 (Labs using **SeqStudio Flex** with SAE enabled must install the latest SAE profile first)
* **GeneMapper ID-X Software** v1.7.3 and earlier, fixed in v1.7.4
Unfortunately, three older, end-of-life product linesβ**3130 Series Data Collection Software** 4.1 and earlier, **ABI PRISM 3100/3100-Avant Data Collection Software** 2.0 and earlier, and **ABI PRISM 310 Data Collection Software** 3.1 and earlierβwill not receive vendor updates. Customers using these systems are strongly advised to implement the recommended compensating controls.
As of August 3, 2026, the **CVE-2026-17583** identifier was listed in **Thermo Fisher's** bulletin but had not yet appeared on **CVE.org** or the **National Vulnerability Database (NVD)**, nor in **CISA's Known Exploited Vulnerabilities catalog**.