Skip to main content
CybersecurityVulnerability Management

Thermo Fisher Fixes Flaw Enabling Near-Undetectable DNA File Tampering

Laboratory workstation with laptop and scientific instruments in bright, neutral lighting.

CVE-2026-17583, rated High with a CVSS v4.0 score of 8.2, is the identifier Thermo Fisher Scientific attached to a vulnerability in select Applied Biosystems human identification software that the company patched in a July 31 security bulletin.

What Thermo Fisher says the flaw allows

Thermo Fisher's bulletin describes a weakness that could allow nearly undetectable changes to .fsa and .hid output files by modifying those files before the analysis software loads them. The vendor says updates implement digital signatures that, moving forward, help customers verify that data files have not been changed. The bulletin does not explain whether files generated before the updates can be validated retroactively or how laboratories should validate them.

Products updated — five supported lines, three left at end-of-life

  • Updated: 3500/3500xL Series Data Collection Software (fixed in 4.0.3); 3730/3730xL Series Data Collection Software (fixed in 5.0.3); SeqStudio Genetic Analyzer Data Collection Software (fixed in 1.2.6); SeqStudio Flex Series Instrument Software (fixed in 1.2.1; labs using SeqStudio Flex with security, audit, and electronic signature (SAE) enabled must first install the latest SAE profile on the SAE Admin Console); and GeneMapper ID-X Software (fixed in v1.7.4).
  • No update: 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and earlier, and ABI PRISM 310 Data Collection Software 3.1 and earlier — each has reached end of life and will receive no vendor update.

Thermo Fisher urged customers to install the applicable updates. For customers unable to implement the updates or use another third-party analysis platform, the company recommended controls covering file custody, storage, access, privilege and network connectivity.

Public demonstration, access requirements, and exploitation status

Thermo Fisher credited Nathan Adams, Kevin Dyer and Laura Gaydosh Combs, together with the U.S. Cybersecurity and Infrastructure Security Agency, with identifying the issue and coordinating disclosure. Thermo Fisher separately told The Wall Street Journal that it knew of no instances in which the vulnerability had been exploited.

The Wall Street Journal reported that Nathan Adams, a systems engineer at Forensic Bioinformatics, tested the issue using a public data set and said his first successful file modification using Anthropic's Claude took about 45 minutes. In a demonstration viewed by the Journal, his code combined scans from two individual DNA profiles into a new file that appeared untouched since 2015; the modified file raised no warning in analysis software used by many laboratories.

Thermo Fisher's bulletin does not specify the access required to perform such modifications. The researchers told the Journal that an attacker would need local or remote access to a laboratory's servers and enough knowledge of how DNA testing works. The reported weakness affects digital records generated from DNA testing, not the underlying physical DNA samples.

How forensic laboratories, CISA/regulators, and researchers are responding

  • Forensic laboratories: Thermo Fisher recommended maintaining chain of custody, storing files on encrypted and password-protected media, restricting access, applying least privilege on instrument and analysis systems, and limiting internet connectivity to trusted sources. Labs using SeqStudio Flex with SAE enabled must also install an updated SAE profile on the SAE Admin Console before applying the instrument update.
  • CISA and regulators: The bulletin credits the U.S. Cybersecurity and Infrastructure Security Agency with coordinating disclosure. As of August 3, 2026, The Hacker News found the Thermo Fisher bulletin but no separate CVE.org or National Vulnerability Database detail page for CVE-2026-17583, and the identifier was not listed in CISA's Known Exploited Vulnerabilities catalog.
  • Researchers and forensic tool developers: The researchers who reported the issue told the Journal the vulnerability likely existed in digital files produced by crime-lab machines since 1995 and said they had not found a way to detect prior tampering if it occurred; Thermo Fisher's bulletin does not confirm that historical scope. The Hacker News found no public primary source linking altered casework to the flaw as of August 3, 2026.

Closing observation: signatures protect future files; the past remains uncertain

The software updates add digital signatures intended to let customers verify that files created after the patches have not been altered. Thermo Fisher's own language is explicit: the signatures will help customers verify files "moving forward." The company and the researchers agree that the reported weakness concerns digital records, and Thermo Fisher told The Wall Street Journal it knows of no exploitation as of the vendor's July 31 bulletin.

What remains open is whether and how laboratories can validate historical files or detect prior tampering. The researchers reported a possible historical scope going back decades but the vendor's bulletin does not confirm that; independent cataloging of the CVE and entries in public vulnerability databases and catalogs were incomplete as of August 3, 2026. For laboratories that handle forensic DNA casework, the immediate steps are clear: apply the vendor updates where available, adopt the custody and access controls Thermo Fisher recommends, and prioritize mitigation plans for instruments that have reached end of life and will receive no update.

Source: The Hacker News — Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable