Thermo Fisher Scientific has issued a high-severity security bulletin after researchers found that data files produced by its Applied Biosystems DNA analysis instruments could be altered without detection.
The bulletin, published on 31 July 2026 and assigned CVE-2026-17583 with a CVSS score of 8.2, covers .fsa and .hid file types generated by several Applied Biosystems Human Identification software products, including the 3500/3500xL and 3730/3730xL Data Collection Software, SeqStudio and SeqStudio Flex systems, and GeneMapper ID-X. Thermo Fisher said modification could occur "if laboratory controls are circumvented" and has released software updates that add digital signatures so labs can verify files have not been changed. Products that have reached end of life, including the 3130 series and ABI PRISM 3100 and 310 systems, will not receive updates.
According to reporting by the Wall Street Journal, the vulnerability is believed by researchers to have existed since 1995, when the affected machine types first came into use, and became easier to exploit as AI coding tools matured. The WSJ reported that Nathan Adams, a systems engineer at Forensic Bioinformatics who worked on the research, used Anthropic's Claude to help write code that altered a DNA file, and said his first successful attempt took around 45 minutes. Thermo Fisher, which was contacted by the researchers in May and acknowledged the issue privately in July, said it has no evidence the vulnerability has been exploited and is working with the US Cybersecurity and Infrastructure Security Agency. The company recommends encrypted storage, restricted access and firewall controls as interim safeguards.
DNA evidence has long been treated as a highly reliable input to criminal investigations and prosecutions, and the WSJ noted that most convictions do not rest on DNA evidence alone. Even so, the finding raises questions for a forensic science system that, according to the WSJ, has more than 200 labs operating without a single national regulator overseeing security practices. Sarah Chu of the Perlmutter Center for Legal Justice told the paper the episode reflects protocols that have not kept pace with security standards adopted elsewhere. Defense attorneys already routinely challenge how DNA evidence is collected and analysed in criminal cases, and a verified method for detecting tampering, once the new digital-signature requirement is in place, may become a factor in how such evidence is scrutinised going forward.
