Thermo Fisher Scientific has shipped fixes for an Applied Biosystems human identification product flaw that opens the door to tampering with DNA data files before analysis software reads them. Thermo Fisher lists CVE-2026-17583 as High severity with a CVSS v4.0 score of 8.2.
According to a July 31 advisory, .fsa and .hid outputs can be modified almost invisibly whenever lab safeguards are bypassed. The patches add digital signatures so customers can verify that data files remain unaltered. Five product lines are covered, including 3500 and 3730 Series Data Collection Software, SeqStudio Genetic Analyzer software, SeqStudio Flex and GeneMapper ID-X. Three end-of-life products receive no fix.
Researcher Nathan Adams of Forensic Bioinformatics told The Wall Street Journal his first successful modification, made with Anthropic’s Claude, took about 45 minutes. In a demo the Journal reviewed, he merged scans from two different DNA profiles into one file that looked untouched since 2015, and widely used lab analysis software flagged nothing.
Thermo Fisher says it knows of no exploited cases. Executing the attack demands local or remote access to a laboratory’s servers plus a genuine grasp of how DNA testing operates, the researchers said. CISA coordinated disclosure.
For labs that cannot update, Thermo Fisher recommends chain-of-custody controls, encrypted and password-protected storage, least-privilege access and limiting internet connectivity to trusted sources.
