Thermo Fisher Scientific: DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data

Thermo Fisher Scientific: DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data

Thermo Fisher Scientific Patches Critical Forensic DNA Software Vulnerability

Thermo Fisher Scientific has disclosed a high-severity security flaw (CVE-2026-17583, CVSS 8.2) in its Applied Biosystems Human Identification (HID) software, which could allow attackers to tamper with forensic DNA analysis files undetected. The vulnerability, published on July 31, 2026, affects .fsa and .hid files key components in DNA profiling used in criminal investigations, paternity testing, and other identification cases.

The flaw impacts multiple software versions, including:

  • 3500/3500xL Series Data Collection Software (v4.0.2 and earlier)
  • 3730/3730xL Series Data Collection Software (v5.0.2 and earlier)
  • SeqStudio Genetic Analyzer Data Collection Software (v1.2.5 and earlier)
  • SeqStudio Flex Series Instrument Software (v1.2.0 and earlier)
  • GeneMapper ID-X Software (v1.7.3 and earlier)

Thermo Fisher has released patched versions (4.0.3, 5.0.3, 1.2.6, 1.2.1, and 1.7.4) that introduce digital signatures to verify file integrity. Users of the SeqStudio Flex system with Secure Analytics Environment (SAE) must first update the SAE profile before applying the patch.

Legacy systems, including the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310, will not receive updates, leaving them permanently vulnerable unless decommissioned or isolated.

For labs unable to patch immediately, Thermo Fisher recommends compensating controls, such as secure chain-of-custody protocols, encrypted storage, restricted file access, least-privilege permissions, and network segmentation.

The vulnerability was responsibly disclosed by researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, in coordination with CISA. Affected organizations are advised to apply updates promptly.

Source: https://cybersecuritynews.com/dna-test-software-vulnerability/

Thermo Fisher Scientific cybersecurity rating report: https://www.rankiteo.com/company/thermo-fisher-scientific

"id": "THE1785781553",
"linkid": "thermo-fisher-scientific",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Labs and organizations using '
                                              'affected software versions',
                        'industry': 'Biotechnology, Forensic Science, DNA '
                                    'Analysis',
                        'name': 'Thermo Fisher Scientific',
                        'type': 'Corporation'}],
 'attack_vector': 'File Tampering',
 'customer_advisories': 'Labs using affected software versions urged to patch '
                        'or implement compensating controls',
 'data_breach': {'data_encryption': 'Recommended as compensating control',
                 'file_types_exposed': ['.fsa', '.hid'],
                 'personally_identifiable_information': 'Potentially (DNA '
                                                        'data)',
                 'sensitivity_of_data': 'High (DNA profiling data)',
                 'type_of_data_compromised': 'Forensic DNA analysis files'},
 'date_publicly_disclosed': '2026-07-31',
 'description': 'Thermo Fisher Scientific has disclosed a high-severity '
                'security flaw (CVE-2026-17583, CVSS 8.2) in its Applied '
                'Biosystems Human Identification (HID) software, which could '
                'allow attackers to tamper with forensic DNA analysis files '
                'undetected. The vulnerability affects .fsa and .hid files key '
                'components in DNA profiling used in criminal investigations, '
                'paternity testing, and other identification cases.',
 'impact': {'brand_reputation_impact': 'High (forensic and legal implications)',
            'data_compromised': 'Forensic DNA analysis files (.fsa and .hid)',
            'legal_liabilities': 'Potential (if tampered evidence used in '
                                 'legal proceedings)',
            'operational_impact': 'Potential undetected tampering with DNA '
                                  'profiling results',
            'systems_affected': 'Applied Biosystems Human Identification (HID) '
                                'software'},
 'investigation_status': 'Vulnerability patched and disclosed',
 'post_incident_analysis': {'corrective_actions': 'Introduction of digital '
                                                  'signatures in patched '
                                                  'versions',
                            'root_causes': 'Lack of digital signatures for '
                                           'file integrity verification in '
                                           'affected software versions'},
 'recommendations': 'Apply patches promptly, implement compensating controls '
                    'for unpatched systems, decommission or isolate legacy '
                    'systems if possible',
 'references': [{'source': 'Thermo Fisher Scientific Advisory'},
                {'source': 'CISA Coordination'}],
 'response': {'communication_strategy': 'Public disclosure and advisory for '
                                        'affected organizations',
              'containment_measures': 'Digital signatures for file integrity '
                                      'verification, secure chain-of-custody '
                                      'protocols, encrypted storage, '
                                      'restricted file access, least-privilege '
                                      'permissions, network segmentation',
              'network_segmentation': 'Recommended for unpatched systems',
              'remediation_measures': 'Patches released for affected software '
                                      'versions (4.0.3, 5.0.3, 1.2.6, 1.2.1, '
                                      'and 1.7.4)',
              'third_party_assistance': 'Researchers Nathan Adams, Kevin Dyer, '
                                        'Laura Gaydosh Combs; CISA'},
 'stakeholder_advisories': 'Affected organizations advised to apply updates '
                           'promptly',
 'title': 'Thermo Fisher Scientific Patches Critical Forensic DNA Software '
          'Vulnerability',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'CVE-2026-17583'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.