HomeSecurityThermo Fisher fixes critical DNA vulnerability

Thermo Fisher fixes critical DNA vulnerability

Thermo Fisher Scientific has released an urgent security update to address the CVE-2026-17583, a serious vulnerability in Applied Biosystems that could allow malicious actors to modify DNA files in a near-undetectable manner. The vulnerability is rated High with a CVSS v4.0 score of 8.2 and affects output files used in forensic DNA analysis processes at hundreds of laboratories across the U.S. and internationally. The scope of the issue is vast, as it is estimated that this workflow is used by the majority of forensic laboratories in the United States.

See also: Zephyr OCPP: Critical vulnerability in CVE-2026-10848 threatens EV chargers

CVE-2026-17583 Thermo Fisher Applied Biosystems DNA files vulnerability
Thermo Fisher fixes critical DNA vulnerability

According to the July 31, 2026, the vulnerability allows for nearly undetectable changes to the .fsa and .hid if laboratory controls are bypassed. These files are the digital results of DNA and are used as evidence in court cases. Thermo Fisher notes that the vulnerability does not affect the biological sample itself, but only the digital chain of custody of the results — which makes the problem extremely insidious.

The vulnerability was discovered by researchers Nathan Adams, Kevin Dyer and Laura Gaydosh Combs, in collaboration with the US Cybersecurity and Infrastructure Security Agency (CISA). Adams, a systems engineer at Forensic Bioinformatics, tested the vulnerability using a public dataset. According to a report by the Wall Street Journal, the first successful file modification using Anthropic Claude took just 45 minutes. In a demonstration watched by the newspaper, the code combined scans from two different DNA profiles into a new file that appeared unchanged since 2015, without triggering any warnings in the analysis software.

CVE-2026-17583: Technical details of the Thermo Fisher vulnerability

CVE -2026-17583 is located in the way Applied Biosystems loads and processes output files before analysis. Specifically, the .fsa and .hid lacked an integrity verification mechanism, allowing an attacker with access to the lab's servers or workstations to modify them before they were loaded by the analysis software. This issue has likely existed in these workflows for a very long time — possibly since the mid-1990s — but modern artificial intelligence tools have made it much easier to exploit.

The researchers noted that they were able to add and remove DNA from records without finding a reliable way to detect tampering afterwards. This means that a malicious actor could theoretically “spoof” an innocent person or “delete” a suspect from DNA analysis results, thereby undermining the legal and evidentiary value of the evidence. The attack requires local or remote access to the lab’s servers, as well as sufficient knowledge of how DNA testing works — it’s not an exploit that can be carried out over the internet by just anyone.

Thermo Fisher has released updates for five supported product lines that add digital signatures to verify file integrity. The updated versions are: 3500/3500xL Series Data Collection Software 4.0.3, 3730/3730xL Series Data Collection Software 5.0.3, SeqStudio Genetic Analyzer Data Collection Software 1.2.6, SeqStudio Flex Series Instrument Software 1.2.1 , and GeneMapper ID-X Software v1.7.4. Three older lines — 3130 Series, ABI PRISM 3100/3100-Avant , and ABI PRISM 310 — have reached end-of-life and will not receive updates.

See also: Phineas Fisher: the hacktivist behind the Hacking Team and FinFisher leaks

Microsoft Patch Tuesday July 2026 records 622 CVEs zero-day vulnerabilities

Thermo Fisher CVE-2026-17583: Impact on forensics and justice

The impact of the CVE-2026-17583 vulnerability extends far beyond the technical boundaries of a typical security bug . It is estimated that the vulnerability could compromise 30 years of DNA evidence , given the long history of the file formats and their widespread use. Forensic science laboratories, prosecutors, defense attorneys, and defendants in cases that rely on the integrity of these files face a fundamental issue of trust in digital evidence.

Security experts who commented on the issue described it as a chain of custody and trust issue: once digital lab results can be tampered with without reliable detection, their legal and evidentiary value is undermined even if the biological sample itself remains intact. Thermo Fisher said it has not identified any cases of exploitation of the vulnerability in practice, but the disclosure alone raises serious questions about cases that have already been closed.

It is worth noting that Thermo Fisher recently faced another controversy over the integrity of scientific data, when researchers documented hundreds of falsified antibody validation images in its online catalog. The company argued at the time that the changes were mainly cosmetic, but the incident highlighted broader concerns about the reliability of scientific data in the industry.

Thermo Fisher: Protection recommendations for laboratories

For laboratories that cannot immediately implement the updates or use third-party analysis platforms, Thermo Fisher recommends a number of security measures. First, maintain a strict chain of custody for all evidence files. Second, store files on encrypted and password-protected media. Third, limit access and implement a principle of least privilege on instrumentation and analysis systems. Fourth, limit internet connectivity to trusted sources only.

Security experts add additional recommendations: enable immutable logging with file hashes and access controls for every transfer, copy, and analysis step; verify file integrity before analysis and before use in court; and review incident response plans for evidence tampering scenarios. Labs should also regularly monitor CISA and Thermo Fisher announcements for further guidance.

See also: Oracle CSPU June 2026: 245 patches for critical vulnerabilities

GhostApproval symlink vulnerability in AI coding agents

An important aspect not addressed in the security bulletin is the issue of retroactive validation : Thermo Fisher states that digital signatures will help verify files “going forward,” without specifying whether files created before the updates can be retroactively validated. This leaves open a critical question for cases based on older files. According to The Hacker News , as of August 3, 2026 , there is still no separate details page for CVE-2026-17583 in the CVE.org database or the National Vulnerability Database , while the identifier does not appear in the CISA ’s Known Exploited Vulnerabilities list .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS