Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583

Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Table of Contents
    Add a header to begin generating the table of contents

    Thermo Fisher Scientific has released signed-file updates for a high-severity flaw in its Applied Biosystems human identification software that can make tampering with DNA data files nearly undetectable. The vulnerability, tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, allows data files to be altered before analysis software loads them, so changes to .fsa and .hid outputs can pass laboratory checks if the surrounding controls are circumvented. The flaw affects digital records generated from DNA testing, not the underlying physical samples.

    Thermo Fisher credited researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, together with CISA, for identifying the issue and coordinating its disclosure. The company told reporters it knows of no instances in which the vulnerability had been exploited, and the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog.

    CVE-2026-17583 Lets an Attacker Alter DNA Files Before They Load

    The weakness sits in the gap between file generation and file analysis. Because analysis software accepts the digital record without an integrity check tied to the producing machine, a modified profile can be loaded and interpreted as a legitimate result. The practical effect, according to the researchers, is that nearly undetectable changes to the evidence files are possible in a laboratory environment, which is why the fix comes as a signed-file update: each new release carries a digital signature so laboratories can verify the software itself has not been altered.

    The Demonstration That Rebuilt an Untouched 2015 DNA Profile

    Nathan Adams, a systems engineer at Forensic Bioinformatics, tested the issue using a public data set and described a first successful file modification that took about 45 minutes using Anthropic’s Claude. In a demonstration viewed by reporters, Adams combined scans from two individual DNA profiles into a new file that appeared untouched since 2015. The modified file raised no warning in analysis software used by many laboratories. The researchers said they had not found a way to detect prior tampering in existing digital files.

    A Flaw in Crime-Lab Files Dating Back to the Mid-1990s

    Adams and his colleagues told reporters the vulnerability likely existed in digital files produced by crime-lab machines since the mid-1990s, meaning the affected format has underpinned forensic casework for decades. The assessment carries particular weight for cold cases and archived evidence, where any file generated on legacy systems would be equally exposed to silent modification.

    Five Updated Product Lines and Three Unsupported Devices

    Thermo Fisher published its security bulletin on July 31 and shipped digital-signature updates for five product lines: 3500/3500xL Data Collection Software at fixed version 4.0.3, 3730/3730xL at 5.0.3, SeqStudio Genetic Analyzer at 1.2.6, SeqStudio Flex Series at 1.2.1, and GeneMapper ID-X at v1.7.4. The breadth of the affected family is significant because the products cover a range of DNA analysis workflows, from genetic analysts running high-throughput runs to forensic labs performing casework on older instrumentation. Three end-of-life products receive no update: the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310, meaning facilities still operating those instruments have no supported fix available and must rely on the compensating controls.

    Mitigation Guidance for Labs That Cannot Update Immediately

    For laboratories that cannot install the fixed versions, Thermo Fisher recommends compensating controls including chain-of-custody documentation, encrypted storage, least-privilege access, and limiting internet connectivity to trusted sources. The company also advises labs to use a third-party analysis platform so that results are reviewed outside the affected toolchain.

    The broader question raised by CVE-2026-17583 is how widely the industry has relied on file formats whose integrity was never cryptographically assured. Investigative bodies that treat digital DNA records as reliable chain-of-custody artifacts may now need to weigh whether verification tooling, independent review platforms, or re-testing of critical samples is warranted for cases resting on older digital evidence. The disclosure does not change the underlying science of DNA analysis, but it shifts part of the evidentiary burden onto the integrity of the record itself, a shift that forensic laboratories will need to build into their handling of digital outputs going forward.

    Related Posts