Applied Biosystems human identification software file-tampering flaw (CVE-2026-17583)
Vulnerability
Summary
Hide ▲
Show ▼
The Applied Biosystems file-tampering flaw in human identification software could let data files be altered before analysis, creating a near-undetectable integrity risk for DNA test outputs. Thermo Fisher Scientific has patched CVE-2026-17583 in five supported product lines, while older end-of-life lines remain unpatched. The issue is rated High with a CVSS v4.0 score of 8.2 and affects .fsa and .hid outputs. Thermo Fisher said it knew of no exploitation when it disclosed the flaw.
Timeline
-
03.08.2026 11:05 1 articles · 1h ago
Researchers demonstrate DNA file modification in about 45 minutes
Technical Analysis UpdateOn August 3, 2026, reporting added technical details about the flaw after Nathan Adams of Forensic Bioinformatics tested it with a public data set and said his first successful file modification using Anthropic's Claude took about 45 minutes. A demonstration showed scans from two individual DNA profiles combined into a new file that appeared untouched since 2015, and the modified file raised no warning in analysis software used by many laboratories. The researchers said an attacker would likely need local or remote access to a laboratory's servers and enough knowledge of DNA testing, while Thermo Fisher said it knew of no instances in which the vulnerability had been exploited.
Show sources
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable — thehackernews.com — 03.08.2026 11:05
-
31.07.2026 03:00 2 articles · 3d ago
Thermo Fisher patches file-tampering flaw in Applied Biosystems software
Initial DisclosureThermo Fisher Scientific issued a July 31 security bulletin and patched CVE-2026-17583 in select Applied Biosystems human identification software after finding that .fsa and .hid data files could be altered before analysis software loads them. The company rated the issue High with a CVSS v4.0 score of 8.2, added digital signatures to five supported product lines, and said three end-of-life data collection products would receive no vendor update. It urged customers to install the applicable updates and, where updates are not feasible, to protect file custody, storage, access, privilege, and network connectivity.
Show sources
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable — thehackernews.com — 03.08.2026 11:05
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable — thehackernews.com — 03.08.2026 11:05