Find notable cyber news and cases, enriched with sources, timelines, and signals.

Applied Biosystems human identification software file-tampering flaw (CVE-2026-17583)

Vulnerability
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The Applied Biosystems file-tampering flaw in human identification software could let data files be altered before analysis, creating a near-undetectable integrity risk for DNA test outputs. Thermo Fisher Scientific has patched CVE-2026-17583 in five supported product lines, while older end-of-life lines remain unpatched. The issue is rated High with a CVSS v4.0 score of 8.2 and affects .fsa and .hid outputs. Thermo Fisher said it knew of no exploitation when it disclosed the flaw.

Timeline

  1. 03.08.2026 11:05 1 articles · 1h ago

    Researchers demonstrate DNA file modification in about 45 minutes

    Technical Analysis Update

    On August 3, 2026, reporting added technical details about the flaw after Nathan Adams of Forensic Bioinformatics tested it with a public data set and said his first successful file modification using Anthropic's Claude took about 45 minutes. A demonstration showed scans from two individual DNA profiles combined into a new file that appeared untouched since 2015, and the modified file raised no warning in analysis software used by many laboratories. The researchers said an attacker would likely need local or remote access to a laboratory's servers and enough knowledge of DNA testing, while Thermo Fisher said it knew of no instances in which the vulnerability had been exploited.

    Show sources
  2. 31.07.2026 03:00 2 articles · 3d ago

    Thermo Fisher patches file-tampering flaw in Applied Biosystems software

    Initial Disclosure

    Thermo Fisher Scientific issued a July 31 security bulletin and patched CVE-2026-17583 in select Applied Biosystems human identification software after finding that .fsa and .hid data files could be altered before analysis software loads them. The company rated the issue High with a CVSS v4.0 score of 8.2, added digital signatures to five supported product lines, and said three end-of-life data collection products would receive no vendor update. It urged customers to install the applicable updates and, where updates are not feasible, to protect file custody, storage, access, privilege, and network connectivity.

    Show sources