Critical Flaw in DNA Analysis Software Threatens Forensic Integrity

Thermo Fisher Scientific has identified a significant security vulnerability in its Applied Biosystems Human Identification (HID) software suite, potentially allowing unauthorized alterations to forensic DNA analysis files. This flaw, designated as CVE-2026-17583, has been assigned a CVSS v4.0 score of 8.2, indicating high severity. The issue was publicly disclosed on July 31, 2026.

The vulnerability pertains to .fsa and .hid file formats produced by Applied Biosystems HID instruments, which are extensively utilized in forensic laboratories for DNA profiling and identification processes. If laboratory security measures are bypassed, an attacker could modify these output files prior to their analysis, with such changes being nearly undetectable through standard review procedures.

Given that these files serve as foundational evidence in criminal investigations, paternity tests, and other identification scenarios, undetected tampering could severely compromise the integrity of forensic conclusions and the chain of custody.

Affected Software Versions and Updates

The vulnerability impacts several versions of Applied Biosystems data collection and analysis software, including:

  • 3500/3500xL Series Data Collection Software (version 4.0.2 and earlier)
  • 3730/3730xL Series Data Collection Software (version 5.0.2 and earlier)
  • SeqStudio Genetic Analyzer Data Collection Software (version 1.2.5 and earlier)
  • SeqStudio Flex Series Instrument Software (version 1.2.0 and earlier)
  • GeneMapper ID-X Software (version 1.7.3 and earlier)

Thermo Fisher has released patched versions to address this issue: 4.0.3, 5.0.3, 1.2.6, 1.2.1, and 1.7.4, respectively. These updates incorporate digital signatures, enabling laboratories to verify that data files have not been altered post-instrumentation.

For users of the SeqStudio Flex system with Secure Analytics Environment (SAE) enabled, it is necessary to first install the latest SAE profile via the SAE Admin Console before applying the update.

Mitigation Strategies for Unpatched Systems

Older platforms, such as the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software, have reached end-of-life status and will not receive patches. Laboratories using these systems are advised to retire or isolate them to mitigate exposure.

For laboratories unable to immediately implement the updates or those utilizing third-party analysis platforms, Thermo Fisher recommends several compensating controls:

  • Maintain a secure chain of custody for files throughout the analysis workflow.
  • Store generated files on encrypted and password-protected media, such as encrypted USB drives or hard drives.
  • Restrict file access to authorized personnel only.
  • Apply least-privilege permissions on systems operating HID instrumentation.
  • Utilize firewall rules or network access control lists to limit internet connectivity to trusted sources exclusively.

Thermo Fisher acknowledged the contributions of researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, along with the Cybersecurity and Infrastructure Security Agency (CISA), for identifying and responsibly disclosing the vulnerability.

The company urges affected organizations to apply the security updates promptly and to contact its product security team for any inquiries.

This incident underscores the critical importance of securing forensic software systems. As digital evidence becomes increasingly central to legal proceedings, ensuring the integrity of analysis tools is paramount. Laboratories must prioritize timely software updates and implement robust security protocols to safeguard against potential data manipulation, thereby preserving the trustworthiness of forensic results.