Researchers altered a forensic DNA evidence file in 45 minutes and the analysis software raised no warning (CVE-2026-17583)
CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering.
AI Analysis
Technical Summary
The vulnerability CVE-2026-17583 affects forensic DNA evidence files (.fsa and .hid) generated by Thermo Fisher's Applied Biosystems human identification instruments. The files can be modified after being written by the instrument but before being loaded by the analysis software, without any warning or detection. Researchers showed that it is possible to merge DNA profiles into a single file that appears authentic and unchanged since 2015. Thermo Fisher's bulletin states that digital signatures have been added to files written after the update to prevent tampering, but no mechanism exists to validate files created before the update. Additionally, some end-of-life products will not receive updates, leaving older forensic evidence files vulnerable to undetected manipulation.
Potential Impact
The vulnerability allows undetectable tampering with forensic DNA evidence files, potentially compromising the integrity of forensic evidence used in legal and investigative contexts. Modified files can merge multiple DNA profiles into one, misleading analysis results without raising any software warnings. The lack of retroactive validation and absence of updates for some end-of-life products means that historical forensic evidence remains at risk, which could undermine trust in forensic processes and outcomes.
Mitigation Recommendations
Thermo Fisher has issued a bulletin implementing digital signatures on forensic DNA evidence files created after the update, which protects new files from tampering. However, no retroactive validation exists for files created prior to the update, and some end-of-life products will not receive patches. Users should apply the update to supported products to ensure new files are protected. For older files, no technical mitigation is currently available; organizations should consider additional procedural controls such as maintaining strict write-access logs and chain-of-custody documentation to detect potential tampering retrospectively.
Researchers altered a forensic DNA evidence file in 45 minutes and the analysis software raised no warning (CVE-2026-17583)
Description
CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering.
Reddit Discussion
Disclosure: I write a daily security newsletter, this was today's issue. The
substance is below, link at the end.
Thermo Fisher's July 31 bulletin covers CVE-2026-17583 (CVSS v4.0 8.2). The
.fsa and .hid files from Applied Biosystems human identification instruments can
be modified between the instrument writing them and the analysis software
loading them, and the change is nearly undetectable. Nothing in the file let the
software confirm the bytes were the ones the instrument wrote. Nathan Adams of
Forensic Bioinformatics told the WSJ his first successful modification took
about 45 minutes, merging scans from two DNA profiles into one file that
presented as untouched since 2015.
The updates add digital signatures, which only protects files written after the
upgrade. The bulletin does not address retroactive validation, the researchers
found no way to detect prior tampering, and these file types have been produced
since 1995. Three end-of-life product lines get no update at all.
Full writeup with the affected versions and remediation order:
Bulletin:
https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf
Most of us have outputs a downstream process treats as authoritative without
checking provenance. For files predating any signing mechanism, write-access
logs on the landing directory are the only retrospective evidence I can build.
What are you using?
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-17583 affects forensic DNA evidence files (.fsa and .hid) generated by Thermo Fisher's Applied Biosystems human identification instruments. The files can be modified after being written by the instrument but before being loaded by the analysis software, without any warning or detection. Researchers showed that it is possible to merge DNA profiles into a single file that appears authentic and unchanged since 2015. Thermo Fisher's bulletin states that digital signatures have been added to files written after the update to prevent tampering, but no mechanism exists to validate files created before the update. Additionally, some end-of-life products will not receive updates, leaving older forensic evidence files vulnerable to undetected manipulation.
Potential Impact
The vulnerability allows undetectable tampering with forensic DNA evidence files, potentially compromising the integrity of forensic evidence used in legal and investigative contexts. Modified files can merge multiple DNA profiles into one, misleading analysis results without raising any software warnings. The lack of retroactive validation and absence of updates for some end-of-life products means that historical forensic evidence remains at risk, which could undermine trust in forensic processes and outcomes.
Mitigation Recommendations
Thermo Fisher has issued a bulletin implementing digital signatures on forensic DNA evidence files created after the update, which protects new files from tampering. However, no retroactive validation exists for files created prior to the update, and some end-of-life products will not receive patches. Users should apply the update to supported products to ensure new files are protected. For older files, no technical mitigation is currently available; organizations should consider additional procedural controls such as maintaining strict write-access logs and chain-of-custody documentation to detect potential tampering retrospectively.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":56,"reasons":["external_link","newsworthy_keywords:cve-,analysis","security_identifier","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["cve-","analysis"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a7219a2bf8831d539238d1c
Added to database: 08/04/2026, 16:56:02 UTC
Last enriched: 08/12/2026, 12:56:55 UTC
Last updated: 09/17/2026, 10:01:29 UTC
Views: 168
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.