INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Thermo Fisher Patches Forensic DNA File Tampering Vulnerability in Software

| 2026-08-04 11:34 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
Thermo Fisher Scientific has released security updates for several Applied Biosystems human identification products after researchers identified a vulnerability that could allow nearly undetectable changes to forensic DNA data files. The issue, tracked as CVE-2026-17583, carries a CVSS score of 8.2 out of 10 (CVSS 4.0). This vulnerability specifically impacts .fsa and .hid output files generated by human-identification software, which are used during human identification analysis, potentially affecting the reliability of forensic results. The attack works by exploiting laboratory controls to be bypassed, allowing these files to be altered after generation but before they are loaded into analysis software. As a result, 3500/3500xL Series Data Collection and 3730/3730xL Series Data Collection versions earlier than 4.0.3 and 5.0.3 respectively need to be updated; SeqStudio Genetic Analyzer Data Collection versions earlier than 1.2.6 also require an update, while GeneMapper ID-X needs updates from v1.7.3 onwards.
Technical Mitigations AI-generated
• Apply digital signatures to .fsa and .hid output files generated by human-identification software, as added in updates for 3500/3500xL Series Data Collection (Version 4.0.3) and SeqStudio Genetic Analyzer Data Collection (Version 1.2.6). • Use CVSS v4.0 scoring to evaluate the severity of potential exploitation. • Monitor for .fsa and .hid output files that have been altered after generation but before they are loaded into analysis software, as a technique to detect tampering attempts. • Block or hunt for unauthorized access to laboratory controls, as an indicator to prevent circumvention of security measures.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-17583CVE-2026-17583
Target & Sectors
Global Scope
Incident Timeline
‎2026/08/04
Thermo Fisher released updates for five Applied Biosystems human identification product lines to address the identified forensic DNA file tampering flaw, tracked as CVE-2026-17583.
infrastructure 4.0.2
infrastructure 4.0.3
infrastructure 5.0.2
infrastructure 5.0.3
infrastructure 1.2.5
infrastructure 1.2.6
infrastructure 1.2.0
infrastructure 1.2.1
infrastructure 7.3
infrastructure 7.4
infrastructure 4.1
infrastructure 2.0
infrastructure 3.1
Tactical Metrics
Metrics
infrastructure
‎4.0.2
Software Version
Metrics
infrastructure
‎4.0.3
Software Version
Metrics
infrastructure
‎5.0.2
Software Version
Metrics
infrastructure
‎5.0.3
Software Version
Metrics
infrastructure
‎1.2.5
Software Version
Metrics
infrastructure
‎1.2.6
Software Version
Metrics
infrastructure
‎1.2.0
Software Version
Metrics
infrastructure
‎1.2.1
Software Version
Metrics
infrastructure
‎7.3
Software Version
Metrics
infrastructure
‎7.4
Software Version
Metrics
infrastructure
‎4.1
Software Version
Metrics
infrastructure
‎2.0
Software Version
Metrics
infrastructure
‎3.1
Software Version