Thermo Fisher Patches Critical Flaw Allowing Undetectable DNA Data Tampering
Thermo Fisher Scientific has released a patch for a critical vulnerability (CVE-2026-17583) in its Applied Biosystems human identification software, which could allow for undetectable tampering of DNA data files.

Thermo Fisher Scientific has addressed a critical vulnerability affecting its Applied Biosystems human identification software, which could allow for the undetectable tampering of DNA data files before they are analyzed. The flaw, tracked as CVE-2026-17583, has a CVSS v4.0 score of 8.2 and could compromise the integrity of forensic and research data by altering results without leaving a trace.
The vulnerability allows for nearly undetectable modifications to .fsa and .hid output files if laboratory controls are bypassed. Thermo Fisher has released updates for five supported product lines, which implement digital signatures to verify data integrity moving forward. However, three older, end-of-life data collection products will not receive an update.
Researchers demonstrated that a file modification could be achieved in approximately 45 minutes using readily available tools. The modified file was then able to pass undetected through analysis software commonly used in laboratories. The researchers noted that an attacker would require local or remote access to a laboratory's servers and a working knowledge of DNA testing procedures to exploit this vulnerability.
The affected product lines include various versions of Data Collection Software for the 3500/3500xL, 3730/3730xL, and SeqStudio series, as well as GeneMapper ID-X Software. Customers using SeqStudio Flex instruments with security, audit, and electronic signature (SAE) enabled must also install the latest SAE profile.
For customers unable to implement the updates or utilize a third-party analysis platform, Thermo Fisher recommends implementing stringent controls. These include maintaining chain of custody, storing files on encrypted and password-protected media, restricting access, enforcing the principle of least privilege on instrument and analysis systems, and limiting network connectivity to trusted sources.
While Thermo Fisher stated it was unaware of any instances where the vulnerability had been exploited, the potential for undetectable data manipulation poses a significant risk to the reliability of forensic evidence and scientific research. The vulnerability affects digital records generated from DNA testing, not the physical DNA samples themselves.
The researchers indicated that the flaw might have existed in digital files produced by crime lab machines for decades, and they had not identified a method to detect prior tampering. Thermo Fisher's bulletin does not confirm this historical scope, nor does it detail how laboratories should validate historical data generated before the updates were applied.
Thermo Fisher credited Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) for their roles in identifying the issue and coordinating its disclosure. As of early August 2026, specific details for CVE-2026-17583 were not yet widely available in public vulnerability databases like CVE.org or the National Vulnerability Database, nor was it listed in CISA's Known Exploited Vulnerabilities catalog.