Thermo Fisher Scientific Software Flaw Jeopardizes Forensic DNA Analysis Integrity
A critical vulnerability in Thermo Fisher Scientific's Applied Biosystems Human Identification software could allow attackers to tamper with forensic DNA analysis data, potentially compromising criminal investigations and paternity tests.

Thermo Fisher Scientific has disclosed a high-severity security flaw affecting its Applied Biosystems Human Identification (HID) software products, warning that attackers could make nearly undetectable modifications to forensic DNA analysis files before they are processed. The vulnerability, tracked as CVE-2026-17583, carries a CVSS v4.0 score of 8.2 and was published on July 31, 2026. The flaw centers on .fsa and .hid file types generated by Applied Biosystems Human Identification instrumentation, which forensic laboratories widely use for DNA profiling and identification workflows.
According to Thermo Fisher, if laboratory controls are circumvented, an attacker could tamper with these output files before they are loaded into analysis software, and the changes would be virtually impossible to detect through normal review. Because .fsa and .hid files underpin evidence used in criminal investigations, paternity testing, and other identification cases, undetected tampering raises serious concerns about the integrity of forensic conclusions and chain-of-custody assurances.
The vulnerability affects multiple generations of Applied Biosystems data collection and analysis software. This includes the 3500/3500xL Series Data Collection Software (version 4.0.2 and earlier), the 3730/3730xL Series Data Collection Software (version 5.0.2 and earlier), the SeqStudio Genetic Analyzer Data Collection Software (version 1.2.5 and earlier), the SeqStudio Flex Series Instrument Software (version 1.2.0 and earlier), and the GeneMapper ID-X Software (version 1.7.3 and earlier).
Thermo Fisher has released patched versions for each of these affected software products. The updates introduce digital signatures that allow laboratories to verify a data file has not been altered after it left the instrument. Users of the SeqStudio Flex system with Secure Analytics Environment (SAE) enabled must first install the latest SAE profile via the SAE Admin Console before applying the update.
Older platforms, including the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software, have reached end-of-life and will not receive patches. These systems remain permanently exposed unless they are retired or isolated from networks.
For laboratories that cannot immediately deploy the update or that rely on third-party analysis platforms, Thermo Fisher recommends implementing layered compensating controls. These include maintaining a secure chain of custody for files throughout the analysis workflow, storing generated files on encrypted and password-protected media, restricting file access to authorized personnel, applying least-privilege permissions on systems running HID instrumentation, and using firewall rules to limit internet connectivity to trusted sources only.
Thermo Fisher credited researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, along with the Cybersecurity and Infrastructure Security Agency (CISA), for identifying and coordinating the responsible disclosure of this issue. The company urged affected organizations to apply the security updates as soon as practical and to contact its product security team for any questions or assistance.