The record
Written from the 1 report below. Nothing here is unsourced.
- Thermo Fisher Scientific has fixed a high-severity flaw in some of its Applied Biosystems DNA identification software that could have let someone quietly alter DNA data files before labs analysed them.
- The company has released updates adding digital signatures for five supported products, but three older, end-of-life products will get no fix.
- Researchers who found the flaw demonstrated combining two people's DNA profiles into a file that looked untouched, and say the weakness may have existed in crime-lab files since 1995.
- Thermo Fisher says it knows of no instances of exploitation, and labs that cannot update are being told to tighten file custody, access and network controls.
What to watch next
- Whether labs using the three unsupported end-of-life products (3130, 3100/3100-Avant, 310 series) adopt workarounds or upgrade
- Whether CVE-2026-17583 gets fuller documentation on CVE.org, the NVD and CISA listings, and whether any exploitation is later confirmed
- Whether Thermo Fisher or researchers clarify how labs can validate DNA files generated before the updates
Coverage1
1 report
English national1
All filed from India
Named United States · Applied Biosystems · Anthropic · Claude · Forensic Bioinformatics · Kevin Dyer · Laura Gaydosh Combs · Nathan Adams · National Vulnerability Database · Thermo Fisher Scientific · The Wall Street Journal · U.S. Cybersecurity and Infrastructure Security Agency
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
