Thermo Fisher Scientific disclosed a high-severity vulnerability, CVE-2026-17583, in several Applied Biosystems Human Identification software products that could allow attackers to alter forensic DNA analysis files with little or no visible trace. The flaw affects .fsa and .hid files generated by forensic instruments and could impact evidence used in criminal investigations, paternity testing, and other identification workflows; researchers said the weakness may affect digital DNA scans dating back to 1995 and warned that manipulated profiles could influence convictions or acquittals.
Thermo Fisher said it has no evidence of active exploitation and assigned the issue a CVSS v4.0 score of 8.2, while releasing patched software that adds digital signatures to help laboratories verify file integrity after data leaves the instrument. The company also warned that some end-of-life platforms will not receive fixes, leaving them exposed unless they are retired or isolated, and recommended compensating controls including strict chain-of-custody procedures, encrypted storage, restricted access, least-privilege permissions, and network segmentation.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Thermo Fisher Scientific disclosed the high-severity vulnerability CVE-2026-17583 affecting Applied Biosystems Human Identification software products, warning that .fsa and .hid forensic DNA analysis files could be tampered with in ways that are virtually impossible to detect through normal review. The company assigned the flaw a CVSS v4.0 score of 8.2 and credited Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and CISA with identifying and coordinating responsible disclosure.
Thermo Fisher said several older platforms, including the 3130 Series and ABI PRISM 3100, 3100-Avant, and 310 Data Collection Software, have reached end-of-life and will not receive fixes for the vulnerability. The company recommended compensating controls such as secure chain-of-custody practices, encrypted storage, restricted access, least-privilege permissions, and network restrictions.
Thermo Fisher released updated versions of affected Applied Biosystems software, including 3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, and GeneMapper ID-X, to address CVE-2026-17583. The patches add digital signatures so laboratories can verify that DNA analysis files were not altered after leaving the instrument.
A group of forensic and computer scientists identified a vulnerability in Thermo Fisher forensic software that could allow undetectable modification of digital DNA evidence, including adding or removing DNA profiles. Researchers said they could not find a reliable way to detect tampering once files were altered.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcehackread.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcedocuments.thermofisher.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.