Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software products, warning that attackers could make nearly undetectable modifications to forensic DNA analysis files before they are processed. The vulnerability, tracked as CVE-2026-17583, carries a CVSS v4.0 score of 8.2 and was published on July 31, 2026.
The flaw centers on .fsa and .hid file types generated by Applied Biosystems Human Identification instrumentation, which forensic laboratories widely use for DNA profiling and identification workflows.
According to Thermo Fisher, if laboratory controls are circumvented, an attacker could tamper with these output files before they are loaded into analysis software, and the changes would be virtually impossible to detect through normal review.
Because .fsa and .hid files underpin evidence used in criminal investigations, paternity testing, and other identification cases, undetected tampering raises serious concerns about the integrity of forensic conclusions and chain-of-custody assurances.
DNA Test Software Vulnerability
The vulnerability affects multiple generations of Applied Biosystems data collection and analysis software, including the 3500/3500xL Series Data Collection Software (version 4.0.2 and earlier), the 3730/3730xL Series Data Collection Software (version 5.0.2 and earlier), the SeqStudio Genetic Analyzer Data Collection Software (version 1.2.5 and earlier), the SeqStudio Flex Series Instrument Software (version 1.2.0 and earlier), and the GeneMapper ID-X Software (version 1.7.3 and earlier).
Thermo Fisher has released patched versions for each: 4.0.3, 5.0.3, 1.2.6, 1.2.1, and 1.7.4, respectively. These updates introduce digital signatures that allow laboratories to verify a data file has not been altered after it left the instrument.
Users of the SeqStudio Flex system with Secure Analytics Environment (SAE) enabled must first install the latest SAE profile via the SAE Admin Console before applying the update.
Older platforms, including the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software, have reached end-of-life and will not receive patches, leaving those systems permanently exposed unless retired or isolated.
For laboratories that cannot immediately deploy the update or that rely on third-party analysis platforms, Thermo Fisher recommends layered compensating controls.
These include maintaining a secure chain of custody for files throughout the analysis workflow, storing generated files on encrypted and password-protected media such as encrypted USB drives or hard drives, restricting file access to authorized personnel, applying least-privilege permissions on systems running HID instrumentation, and using firewall rules or network access control lists to limit internet connectivity to trusted sources only.
Thermo Fisher credited researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, along with the Cybersecurity and Infrastructure Security Agency (CISA), for identifying and coordinating responsible disclosure of the issue.
The company urged affected organizations to apply the security updates as soon as practical and to contact its product security team for any questions.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data appeared first on Cyber Security News.



