Thermo Fisher Scientific has addressed a critical vulnerability, tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, in its Applied Biosystems human identification software. This flaw could permit data files to be modified before analysis software loads them, making changes to .fsa and .hid outputs nearly undetectable if laboratory controls are bypassed. The company released a security bulletin on July 31 detailing the issue and available fixes.
The vulnerability's primary concern is its potential to compromise the integrity of DNA data. Researchers demonstrated that it was possible to combine scans from two individual DNA profiles into a new file that appeared unaltered, even to analysis software widely used in laboratories. This could have significant implications for forensic investigations, paternity testing, and other applications relying on accurate human identification data.
Thermo Fisher has provided updates for five supported Applied Biosystems human identification product lines, including versions of 3500/3500xL, 3730/3730xL, and SeqStudio Genetic Analyzer Data Collection Software. These updates introduce digital signatures to help customers verify that data files have not been changed. Three end-of-life data collection products will not receive vendor updates. For customers unable to update or using third-party analysis platforms, Thermo Fisher recommends implementing controls for file custody, storage, access, privilege, and network connectivity.
The vulnerability was identified by Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, in collaboration with the U.S. Cybersecurity and Infrastructure Security Agency (CISA). While Thermo Fisher stated it knows of no instances where the vulnerability has been exploited, the researchers demonstrated the ease of exploitation, with one successful file modification taking approximately 45 minutes using Anthropic's Claude. Exploitation requires local or remote access to laboratory servers and knowledge of DNA testing processes.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Thermo Fisher Scientific has released patches for a high-severity vulnerability (CVE-2026-17583) in its Applied Biosystems human identification software that could allow nearly undetectable alteration of DNA data files. The flaw, rated 8.2 CVSS v4.0, affects five supported product lines and could enable malicious actors to combine or modify DNA profiles without detection, impacting forensic and diagnostic integrity.