CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Thermo Fisher Patches High-Severity DNA File Tampering Flaw CVE-2026-17583

August 3, 2026

Thermo Fisher Scientific has released security updates to address a high-severity vulnerability (CVE-2026-17583, CVSS v4.0 score 8.2) in select Applied Biosystems human identification software. The flaw could allow attackers to alter DNA data files (.fsa and .hid) in a way that is nearly undetectable before analysis software loads them, potentially compromising forensic investigations.

The vulnerability was discovered by Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, with coordination from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The researchers demonstrated that an attacker with local or remote access to a laboratory’s servers could modify DNA profiles without triggering warnings in analysis software. In one demonstration, a modified file appeared untouched since 2015.

Thermo Fisher has released updates for five supported product lines, adding digital signatures to help verify file integrity. Affected products include:

  • 3500/3500xL Series Data Collection Software (fixed in 4.0.3)
  • 3730/3730xL Series Data Collection Software (fixed in 5.0.3)
  • SeqStudio Genetic Analyzer Data Collection Software (fixed in 1.2.6)
  • SeqStudio Flex Series Instrument Software (fixed in 1.2.1)
  • GeneMapper ID-X Software (fixed in v1.7.4)

Three end-of-life products (3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310) will not receive updates. For customers unable to apply patches, Thermo Fisher recommends implementing strict file custody, storage, access, and network controls.

As of August 3, 2026, there is no evidence of exploitation in the wild, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The flaw is believed to have existed since 1995, potentially affecting historical digital records. Thermo Fisher’s bulletin does not specify whether files generated before the updates can be retroactively validated.

CVEs: CVE-2026-17583, CVE-2026-50522

Companies: Thermo Fisher Scientific, Applied Biosystems, Forensic Bioinformatics, Anthropic

Products: 3500/3500xL Series Data Collection Software, 3730/3730xL Series Data Collection Software, SeqStudio Genetic Analyzer Data Collection Software, SeqStudio Flex Series Instrument Software, GeneMapper ID-X Software, 3130 Series Data Collection Software, ABI PRISM 3100/3100-Avant Data Collection Software, ABI PRISM 310 Data Collection Software