CVE-2026-17583 is a high-severity integrity vulnerability affecting multiple Thermo Fisher Applied Biosystems Human Identification and genetic analyzer software products. The flaw exists because generated .fsa and .hid output files lack sufficient integrity protection and can be modified after creation without reliable detection. As a result, an attacker who gains the ability to alter these files between generation and downstream analysis can tamper with DNA analysis data before it is processed by analysis software. The issue affects several supported product lines as well as some end-of-life platforms. Thermo Fisher addressed the vulnerability in supported products by introducing digital-signature protections for newly generated files so laboratories can verify whether output data has been altered after leaving the instrument.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers and associated data collection/software products where editable .fsa/.hid output files lack integrity protection, allowing tampering with DNA data and potentially causing inaccurate DNA test results.
A vulnerability in Thermo Fisher Scientific Applied Biosystems human identification products that affects .fsa and .hid output files, allowing post-generation tampering before analysis and potentially undermining the reliability of forensic DNA results.
A high-severity integrity flaw in Thermo Fisher Applied Biosystems Human Identification software that could allow attackers to make nearly undetectable modifications to .fsa and .hid forensic DNA analysis files before processing, undermining forensic result integrity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.