< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

Thermo Fisher Fixes Critical Forensic DNA Software Vulnerability

Thermo Fisher Scientific disclosed a critical security flaw (CVE‑2026‑17583) in the file formats used by its forensic DNA analysis instruments. The vulnerability allowed an attacker to alter raw DNA profile files – for example by merging two separate profiles and back‑dating the metadata to 2015 – without triggering any warning in the downstream GeneMapper ID‑X software. The flaw could affect decades of DNA evidence used in criminal investigations.

The weakness was uncovered by external security researchers Nathan Adams, Kevin Dyer and Laura Gaydosh Combs, who demonstrated the exploit in about 45 minutes using publicly available datasets and an AI assistant. Their findings were coordinated with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) before public disclosure on 31 July 2026. Thermo Fisher’s response adds digital signatures to the raw data files and updates GeneMapper ID‑X to verify those signatures on opening. The company also advises users to encrypt stored files, restrict access rights, and tighten firewall settings.

The fix restores integrity checks between the Applied Biosystems instruments and the analysis software, addressing a gap that could have compromised forensic evidence and subsequent legal outcomes.

Entities: Applied Biosystems · CISA · GeneMapper ID‑X · Nathan Adams · Thermo Fisher Scientific