Intelligence
highVulnerabilityActive

DNA Analysis Software Flaw Enables Undetectable Forensic Data Tampering

CVE-2026-17583 can allow undetected modification of forensic DNA output files when an attacker has local or remote access to a laboratory server. Supported products have fixes, but three end-of-life Applied Biosystems product lines remain unpatched.

S
Sebastion

CVE References

Affected

Thermo Fisher Scientific Applied Biosystems human identification software

Thermo Fisher's July updates address an integrity issue in supported forensic DNA analysis products. CVE-2026-17583 allows modification of .fsa trace-data and .hid results files before downstream analysis, potentially leaving the changes undetected by the analysis software. Exploitation requires local or remote access to a laboratory server, so an attacker must first cross the lab's access controls.

The underlying flaw may date to 1995. Thermo Fisher said it was not aware of any exploitation, but the possibility of long-standing exposure makes review of access records and file provenance appropriate for affected laboratories.

Three end-of-life product lines remain unpatched: the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310. Their continued exposure means the overall status remains active despite remediation for supported products.

Laboratories should apply Thermo Fisher's updates and mitigations for supported products. Where an unpatched end-of-life system remains in service, operators should follow the vendor's replacement guidance, restrict local and remote server access, segment the system, and monitor access and changes to output files.