Thermo Fisher Scientific has disclosed a high-severity security flaw impacting several Applied Biosystems Human Identification software products. The vulnerability, identified as CVE-2026-17583, carries a CVSS score of 8.2 and was published on July 31, 2026. Because .fsa and .hid files underpin evidence crucial in criminal investigations, paternity testing, and other identification cases, undetected tampering poses significant concerns about the integrity of forensic conclusions and chain-of-custody assurances.
DNA Test Software Vulnerability The vulnerability impacts multiple generations of Applied Biosystems data collection and analysis software, including the 3500/3500xL Series Data Collection Software (versions 4.0.2 and earlier), the 3730/3730xL Series Data Collection Software (versions 5.0.2 and earlier), the SeqStudio Genetic Analyzer Data Collection Software (version 1.2.5 and earlier), the SeqStudio Flex Series Instrument Software (version 1.2.0 and earlier), and the GeneMapper ID-X Software (version 1.7.3 and earlier). Older platforms, including the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software, have reached end-of-life and will not receive patches, leaving those systems permanently exposed unless retired or isolated.
Thermo Fisher acknowledged researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs, along with the Cybersecurity and Infrastructure Security Agency (CISA), for identifying and coordinating responsible disclosure of the issue.












