Thermo Fisher Scientific has shipped fixes for an Applied Biosystems human identification product flaw that opens the door to tampering with DNA data files before analysis software reads them. The vendor rates the issue, tracked as CVE-2026-17583, High with a CVSS v4.0 score of 8.2.
According to a July 31 advisory, .fsa and .hid outputs can be modified almost invisibly whenever lab safeguards are bypassed. The updates bolt on digital signatures that let customers confirm files have not been touched. Five product lines are covered, including 3500 and 3730 Series Data Collection Software, SeqStudio Genetic Analyzer software, SeqStudio Flex and GeneMapper ID-X. Three end-of-life products receive no fix.
Researcher Nathan Adams of Forensic Bioinformatics told The Wall Street Journal his first successful modification, made with Anthropic’s Claude, took about 45 minutes. In a demo the Journal reviewed, he merged scans from two different DNA profiles into one file that looked untouched since 2015, and widely used lab analysis software flagged nothing.
Thermo Fisher says it knows of no exploited cases. The researchers noted that pulling this off requires local or remote access to a lab’s servers and real familiarity with how DNA testing works. CISA coordinated disclosure.
For labs that cannot update, Thermo Fisher recommends chain-of-custody controls, encrypted and password-protected storage, least-privilege access and limiting internet connectivity to trusted sources.
