# Thermo Fisher Genetic Analyzers Allow DNA File Tampering

Published: 2026-08-04 · Severity: medium · Sectors: healthcare
Canonical: https://vorant.io/reports/31e1409c-d65c-53a6-8cee-fb5cab4288d8/thermo-fisher-genetic-analyzers-allow-dna-file-tampering

> A missing integrity check in Thermo Fisher Applied Biosystems genetic analyzer software lets attackers modify .fsa/.hid files, corrupting DNA test results.

CISA published an advisory for multiple Thermo Fisher Applied Biosystems genetic analyzer products, disclosing a vulnerability (CVE-2026-17583) tied to CWE-353, Missing Support for Integrity Check. The affected software fails to protect .fsa/.hid output files from unauthorized modification, meaning an attacker with access to these files could alter DNA data and produce inaccurate test outcomes. The affected product line spans multiple Data Collection Software versions used in the Applied Biosystems 3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, GeneMapper ID-X, 3130 Series, and legacy ABI PRISM instruments, deployed worldwide in healthcare and public health laboratories.

Thermo Fisher has released patched versions for several actively supported products that add digital signatures to instrument software, allowing verification that data files have not been tampered with. However, three older product lines (3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310) are end-of-life and will not receive fixes, leaving those deployments reliant on interim mitigations such as chain-of-custody controls, encrypted storage, least-privilege access, and network isolation.

CISA notes the vulnerability is not remotely exploitable and no public exploitation has been reported. The impact is primarily one of data integrity in forensic and clinical DNA analysis workflows rather than a network intrusion vector, but given the sensitivity of DNA testing (forensic, paternity, clinical diagnostics), tampering could have significant downstream consequences if exploited by an insider or someone with local file access.

## Mentioned in this report

- Vulnerabilities: CVE-2026-17583

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/31e1409c-d65c-53a6-8cee-fb5cab4288d8/thermo-fisher-genetic-analyzers-allow-dna-file-tampering.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
