Thermo Fisher Scientific has recently identified a significant security vulnerability in several of its Applied Biosystems Human Identification (HID) software products. This flaw, classified as CVE-2026-17583 with a CVSS v4.0 score of 8.2, was disclosed on July 31, 2026. It allows potential attackers to make subtle modifications to forensic DNA analysis files, which could go unnoticed before these files are processed.
Implications of the Software Flaw
The vulnerability particularly affects .fsa and .hid files generated by Applied Biosystems Human Identification instruments. These files are crucial in forensic laboratories for DNA profiling and identification purposes. If an attacker bypasses laboratory controls, they could alter these files in a manner that standard procedural reviews would fail to detect.
This issue is alarming as these file types form the basis for evidence in criminal investigations, paternity testing, and other identity verification scenarios. Any tampering with these files can significantly compromise the reliability of forensic conclusions and disrupt the chain of custody.
Affected Software and Patch Releases
The security flaw impacts multiple versions of Applied Biosystems software, including the 3500/3500xL Series, 3730/3730xL Series, SeqStudio Genetic Analyzer, SeqStudio Flex Series, and GeneMapper ID-X Software. Thermo Fisher has issued patched updates for these systems, introducing digital signatures to verify file integrity post-processing.
For users of the SeqStudio Flex system utilizing the Secure Analytics Environment (SAE), it is necessary to update the SAE profile before applying the software patch. Unfortunately, older systems such as the 3130 Series and ABI PRISM models have reached end-of-life and will not receive updates, leaving them vulnerable unless decommissioned or isolated.
Recommendations for Mitigation
For laboratories unable to immediately implement the updates or using third-party platforms, Thermo Fisher advises deploying layered security measures. These include maintaining a secure chain of custody, storing files on encrypted media, restricting access to authorized personnel, applying least-privilege permissions, and using firewall rules to control network access.
The vulnerability was identified through the efforts of researchers Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and the Cybersecurity and Infrastructure Security Agency (CISA). Thermo Fisher recommends that affected organizations promptly apply the security patches and reach out to their product security team for further assistance.
By addressing these vulnerabilities, laboratories can ensure the integrity of their forensic data and maintain confidence in their analytical processes.
