Thermo Fisher Patches DNA File Forgery Flaw

Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- Thermo Fisher patched CVE-2026-17583, rated High (CVSS v4.0 score of 8.2), in select Applied Biosystems human identification software; the flaw could allow nearly undetectable changes to .fsa and .hid output files before analysis software loads them.
- Five supported product lines received updates adding digital signatures—3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, and GeneMapper ID-X—while three end-of-life lines (3130, ABI PRISM 3100/3100-Avant, ABI PRISM 310) will receive no vendor update.
- Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, working with the U.S. Cybersecurity and Infrastructure Security Agency, identified the issue and coordinated disclosure.
- Nathan Adams, a systems engineer at Forensic Bioinformatics, demonstrated the attack using Anthropic's Claude, completing his first successful file modification in about 45 minutes and combining two individual DNA profiles into a file that appeared untouched since 2015.
- The researchers told The Wall Street Journal the vulnerability likely existed in crime-lab digital files since 1995 and that they had found no way to detect prior tampering if it occurred.
- Thermo Fisher told the Wall Street Journal it knew of no instances of exploitation, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog; Thermo Fisher's public bulletin does not explain whether pre-patch files can be validated retroactively.
Why it matters: For the five supported product lines, digital signatures now enable forward verification—but three end-of-life product lines get no update, and the researchers said no method exists to detect tampering in DNA files generated since 1995. Crime labs running unpatched systems have no published way to confirm the integrity of historical casework.




