Press play to start listening
Thermo Fisher Scientific has released security updates for several Applied Biosystems human identification products after researchers identified a vulnerability that could allow nearly undetectable changes to forensic DNA data files. The issue, tracked as CVE-2026-17583, carries a CVSS score of 8.2 out of 10 (CVSS 4.0).
The vulnerability specifically impacts .fsa and .hid output files generated by human-identification software. Thermo Fisher credited Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and the Cybersecurity and Infrastructure Security Agency (CISA) with identifying and coordinating disclosure of the vulnerability.
Exploitation would require laboratory controls to be bypassed, allowing .fsa and .hid files to be altered after generation but before they are loaded into analysis software. Because these files are used during human identification analysis, undetected changes could affect the reliability of forensic results.
Affected Software and Updates
The company released updates for five supported software products. The updates add digital signatures that allow laboratories to verify whether files have been modified. This protection applies to files generated after the updates are installed.
- 3500/3500xL Series Data Collection: Version 4.0.2 and earlier need to be updated to version 4.0.3.
- 3730/3730xL Series Data Collection: Version 5.0.2 and earlier need to be updated to version 5.0.3.
- SeqStudio Genetic Analyzer Data Collection: Versions 1.2.5 and earlier need to be updated to version 1.2.6.
- SeqStudio Flex Series Instrument: Versions 1.2.0 and earlier need to be updated to version 1.2.1.
- GeneMapper ID-X: Versions v1.7.3 and earlier need to be updated to version v1.7.4.
For the SeqStudio Flex system with Security, Audit, and E-signature (SAE) features enabled, “the user must first install the latest SAE profile on the SAE Admin Console before installing the update,” the company noted in its official advisory (PDF).
End-of-Life Software Will Not Receive Updates
However, these fixes don’t apply to all devices. The company has clarified that not all software will receive a patch and that three older systems will not receive security updates because Thermo Fisher Scientific no longer supports them.
These unsupported programs include the 3130 Series Data Collection version 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection version 2.0 and earlier, and ABI PRISM 310 Data Collection version 3.1 and earlier.
“As this software has reached its end-of-life and is no longer supported by Thermo Fisher Scientific, no update will be provided,” the company explained in the advisory.
For laboratories unable to install the updates immediately, or those using unsupported software, Thermo Fisher recommends maintaining a secure chain of custody, storing files on encrypted and password-protected media, restricting access to authorized personnel, applying least-privilege permissions, and limiting internet connectivity to trusted sources through firewall rules and network access controls.
(Photo by 铮 夏 on Unsplash)