CVE Tools

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

The Hacker NewsBy The Hacker News

PatchApplied Biosystems software

Our summary

Thermo Fisher Scientific has issued a patch for a high-severity vulnerability in certain Applied Biosystems human identification software that could enable attackers to alter .fsa and .hid files before analysis without detection. Tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, the flaw allows unauthorized modifications to DNA test output if lab security controls are bypassed. The company has updated five product lines with digital signature support to verify file integrity going forward, while three end-of-life products remain unpatched. Researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs worked alongside CISA to disclose the issue responsibly. Thermo Fisher warns that prior data may not be verifiable retroactively and urges users to apply updates or adopt alternative validation methods.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store