Thermo Fisher DNA Software Flaw Allowed Undetectable Evidence Tampering Thermo Fisher Scientific patched a high-severity vulnerability (CVE-2026-17583, CVSS 8.2) in its Applied Biosystems DNA analysis software that allowed anyone with server access to alter evidence files without detection, potentially compromising criminal convictions. Researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs demonstrated the flaw, with Adams using Anthropic's Claude AI to modify files in about 45 minutes. Patches add digital signatures to five supported product lines, but three end-of-life lines (3130 Series, ABI PRISM 3100/3100-Avant, ABI PRISM 310) remain vulnerable, and Thermo Fisher reported no known exploitation. Thermo Fisher just patched a flaw in its crime-lab DNA software that let anyone with server access alter evidence files without a trace — the same evidence prosecutors use to put Americans behind bars. For decades, juries have been told DNA doesn't lie. The files carrying that DNA data, it turns out, could. Researchers demonstrated that .fsa and .hid output files from Thermo Fisher's Applied Biosystems product lines could be modified before analysis software loads them, and the altered files raised no warnings in the lab software used across the country. The vulnerability, tracked as CVE-2026-17583 and rated High with a CVSS score of 8.2, was identified by Nathan Adams of Forensic Bioinformatics, along with researchers Kevin Dyer and Laura Gaydosh Combs, in coordination with CISA. Adams told The Wall Street Journal that his first successful file modification, using Anthropic's Claude AI, took about 45 minutes. In a demonstration viewed by the Journal, his code combined scans from two separate DNA profiles into a new file that appeared untouched since 2015. The analysis software used by many laboratories flagged nothing. The Hacker News reported the technical details straight: five supported product lines now receive updates that add digital signatures, allowing labs to verify files haven't been changed. Three end-of-life product lines — the 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 — get nothing. No patch, no fix. Labs still running that older equipment stay vulnerable unless they implement manual controls around file custody, encryption, access privileges, and network connectivity. The Verge framed the risk as 30 years of DNA evidence exposed to hacking, emphasizing that bad actors could frame the innocent or erase the guilty. That's the real stake, even if the required access — local or remote lab server access plus DNA testing knowledge — narrows the pool of potential attackers. The Hacker News noted that detail; The Verge acknowledged it but buried the qualifier. Thermo Fisher told the Journal it knows of no instance where the vulnerability was exploited. That's the company line. But the absence of evidence isn't evidence of absence. The flaw existed for years in software that underpins criminal convictions. No audit mechanism existed to catch tampering. The patch adds digital signatures going forward — it does nothing to verify whether files analyzed yesterday, last year, or a decade ago were legitimate. Thermo Fisher's recommended fallback — chain-of-custody controls, encrypted storage, least-privilege access, restricted internet connectivity — amounts to telling labs to lock the barn door after the horse may already be gone. For the three product lines receiving no update, that's all there is. The question nobody in the forensic establishment wants to answer: how many Americans are sitting in cells right now on evidence generated by systems that could have been silently altered, with no way to prove it?