# Thermo Fisher DNA forensic software vulnerability

> Live situation record from CLSTR: https://clstr.news/situations/thermo-fisher-dna-forensic-software-vulnerability
> Updated: 2026-08-09T04:10:03.000Z. Sources: 8. Developments: 2.

Security researchers discovered a critical vulnerability (CVE-2026-17583) in Thermo Fisher Scientific's forensic DNA analysis software and file formats. The flaw allowed attackers to manipulate raw DNA profile files, such as merging profiles or back-dating metadata, without detection by the GeneMapper ID-X software. Researchers demonstrated that AI tools could be used to perform these manipulations in under 45 minutes.

The vulnerability impacts .fsa and .hid file formats that have been used for forensic fragment analysis since 1995. Because of this long-standing usage, researchers noted that it is currently impossible to verify whether older digital evidence in criminal cases has been altered.

Thermo Fisher Scientific released security patches for five supported product lines, including the 3500- and 3730-series and GeneMapper ID-X, implementing digital signatures to ensure file integrity. However, three discontinued legacy product lines—the 3130 series, ABI PRISM 3100, 3100-Avant, and 310—will not receive updates, leaving laboratories using that equipment vulnerable. The company stated it is unaware of any real-world exploitation of the flaw.

## Timeline

### 2026-08-09: AI vulnerability allows manipulation of digital DNA forensic evidence

Researchers discovered that AI can manipulate digital DNA forensic files without detection, potentially compromising decades of criminal evidence. Thermo Fisher Scientific has issued patches for several product

4 sources. https://clstr.news/cluster/ai-vulnerability-allows-manipulation-of-digital-dna-forensic-evidence

### 2026-08-03: Thermo Fisher Fixes Critical Forensic DNA Software Vulnerability

Thermo Fisher patched a forensic DNA software flaw that let attackers silently alter profile files, after researchers disclosed the issue and CISA coordinated the fix.

4 sources. https://clstr.news/cluster/thermo-fisher-fixes-critical-forensic-dna-software-vulnerability

---
Cite as: Thermo Fisher DNA forensic software vulnerability. CLSTR, https://clstr.news/situations/thermo-fisher-dna-forensic-software-vulnerability
