Thermo Fisher Scientific has fixed a vulnerability in DNA testing software that could allow attackers to alter case files without detection, according to a security bulletin published July 31. The flaw, tracked as CVE-2026-17583 and rated High with a CVSS score of 8.2, affected Applied Biosystems human identification software used in forensic laboratories. The company said nearly undetectable changes to .fsa and .hid output files could occur if laboratory controls were bypassed.

Five supported product lines received updates that add digital signatures to verify file integrity, while three end-of-life data collection products will get no vendor fix. The patched systems include the 3500/3500xL Series Data Collection Software (fixed in version 4.0.3), 3730/3730xL Series (fixed in 5.0.3), SeqStudio Genetic Analyzer (fixed in 1.2.6), SeqStudio Flex Series (fixed in 1.2.1), and GeneMapper ID-X Software (fixed in v1.7.4). The three older lines receiving no updates are the 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and earlier, and ABI PRISM 310 Data Collection Software 3.1 and earlier. Thermo Fisher credited Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, along with the U.S. Cybersecurity and Infrastructure Security Agency, with identifying the issue and coordinating disclosure.

The company told The Wall Street Journal it knew of no instances where the vulnerability had been exploited. Nathan Adams, a systems engineer at Forensic Bioinformatics, demonstrated the flaw using a public data set, telling the Journal his first successful file modification using Anthropic's Claude took about 45 minutes. In a demonstration viewed by the outlet, his code merged scans from two individual DNA profiles into a new file that appeared unchanged since 2015, raising no warning in analysis software used by many labs. Researchers told the Journal an attacker would need local or remote access to laboratory servers and sufficient knowledge of DNA testing processes. The bulletin states the files can be modified before analysis software loads them, and the updates implement digital signatures that help customers verify files haven't been changed going forward.

The weakness affects digital records generated from DNA testing, not the underlying physical samples themselves. Researchers told the Journal the vulnerability likely existed in digital files produced by crime-lab machines since 1995 and that they hadn't found a method to detect prior tampering if it occurred. Thermo Fisher's bulletin doesn't confirm that historical scope or explain whether files generated before the updates can be validated retroactively. For customers unable to install the updates or use another third-party analysis platform, the company recommends maintaining chain of custody, storing files on encrypted and password-protected media, restricting access, applying least privilege on instrument and analysis systems, and limiting internet connectivity to trusted sources. As of August 3, the identifier wasn't listed in CISA's Known Exploited Vulnerabilities catalog, and no public primary source had linked altered casework to the flaw.