Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has issued a patch for a high-severity vulnerability in certain Applied Biosystems human identification software that could enable attackers to alter .fsa and .hid files before analysis without detection. Tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, the flaw allows unauthorized modifications to DNA test output if lab security controls are bypassed. The company has updated five product lines with digital signature support to verify file integrity going forward, while three end-of-life products remain unpatched. Researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs worked alongside CISA to disclose the issue responsibly. Thermo Fisher warns that prior data may not be verifiable retroactively and urges users to apply updates or adopt alternative validation methods.