Thermo Fisher Scientific has fixed a security issue in a portion of Applied Biosystems human identification software. The risk: manipulating DNA files could be possible before analysis tools load the data, using changes that, according to the vendor, are difficult to recognize.
In the security bulletin dated July 31, the issue is recorded as CVE-2026-17583 and the impact is rated High (CVSS v4.0 score 8.2). The updates add digital signatures so laboratories can verify their input files more reliably.
What went wrong with DNA data?
The vulnerability lies in selected data collection components and the output they generate (.fsa and .hid files). The core problem is that files can be modified before the analysis software processes them. If a lab check is bypassed, altered files can pass through the workflow without the analysis tool automatically raising an alarm.
Thermo Fisher states that changes that are almost undetectable may be possible. The vendor frames this as a scenario where attackers don’t so much tamper with the physical specimen, but with the digital records produced by DNA testing processes.
Which software versions were updated?
According to Thermo Fisher, five product lines within Applied Biosystems have been updated with versions that include digital signatures:
- 3500/3500xL Data Collection Software: version 4.0.2 and earlier, fixed in 4.0.3
- 3730/3730xL Data Collection Software: version 5.0.2 and earlier, fixed in 5.0.3
- SeqStudio Genetic Analyzer Data Collection Software: version 1.2.5 and earlier, fixed in 1.2.6
- SeqStudio Flex Instrument Software: version 1.2.0 and earlier, fixed in 1.2.1. For Labs with security, audit, and electronic signature (SAE) enabled: first install the latest SAE profile on the SAE Admin Console.
- GeneMapper ID-X: version 1.7.3 and earlier, fixed in v1.7.4
Three older lines do not receive updates because, according to Thermo Fisher, they are end-of-life:
- 3130 Series Data Collection Software: version 4.1 and earlier
- ABI PRISM 3100/3100-Avant Data Collection Software: version 2.0 and earlier
- ABI PRISM 310 Data Collection Software: version 3.1 and earlier
Why digital signatures make the difference
Thermo Fisher expects digital signatures will help customers determine that files have not been modified. In other words: where tampering was previously possible before analysis software loaded the input, the software must now be able to check more effectively whether the data is still authentic.
An important nuance: the bulletin does not clearly explain how (or whether) files that were already produced before the update can be validated retroactively. It also does not specify the exact access level required; however, the bulletin and additional reporting provide context about the kind of knowledge an attacker would need.
Has misuse already occurred?
The public bulletin does not discuss active exploitation. Thermo Fisher separately tells the press that no cases are known where the vulnerability has been exploited.
The description of possible attack scenarios is supported by research shared in reporting. That research tested how changes in DNA profile data could lead to files that appear unaltered, while analysis tools would not issue any warning. Thermo Fisher does not confirm this as evidence of exploitation in the wild, but it does underline the importance of applying the patch.
If you can’t patch: additional protective measures
Thermo Fisher advises customers who cannot update right away or who use an alternative platform to strongly organize their process around file management. Think about measures at the level of the case file and the data flow—not only at the software layer.
Concretely, the vendor recommends, among other things:
- ensuring chain of custody;
- storing data on encrypted media protected with a password;
- applying access restrictions on who may read or modify;
- using least privilege on instrument and analysis machines;
- limiting internet connectivity to trusted sources.
This approach aligns with a broader security principle: if data can be manipulated before analysis starts, you need to demonstrate data reliability with controls around storage, access, and transfer.
Why this matters for software supply chain security
This case fits within the domain of software supply chain security: not only the “core” of a network or the endpoint matters—so do the tools and the processing of digital artifacts in a chain, which determine whether evidence remains trustworthy.
If files in a workflow can be altered unnoticed, that creates a risk for the integrity of the data. This is similar to other scenarios where trust in software behavior or management processes is exploited. On our site, for example, we also cover implicit trust and loss of control in security chains, such as in CaptiveCrunch and Wi‑Fi gateway attacks. While the technique differs, the underlying pattern is recognizable: if an intermediary step does not enforce strong verification, an attacker can misuse that step.
What you can do today
If you use one of the supported Applied Biosystems lines, the action is to install the relevant updates that add digital signatures in a timely manner. Also review your dependencies: for SeqStudio Flex with SAE enabled, an extra preparatory step is required via the SAE Admin Console.
Is your environment running end-of-life variants? Then patching is not available. In that case, it becomes even more important to put the recommendations into practice around chain of custody, encrypted storage, access control, least privilege, and network restrictions. In addition, document how you assess the integrity of case files and what checks you perform when transferring between systems.
Conclusion
Thermo Fisher has patched a flaw that could make manipulating DNA files nearly undetectable before analysis tools load the data. The update approach using digital signatures is intended to improve verification of input files, although validation of historical files is still unclear in the bulletin.
For laboratories, the key takeaway is: patch where possible, and if that is not possible, compensate with strict governance around file management and access rights. That way, you protect the integrity of digital DNA records and maintain control over the entire data chain.
