Thermo Fisher Scientific has released a patch for a security flaw affecting its Applied Biosystems human identification software, which could let users modify data files before they are loaded by analysis tools.
The vulnerability, tracked as CVE-2026-17583, permits almost undetectable changes to .fsa and .hid output files if laboratory controls are bypassed.
In a security bulletin issued on July 31, the vendor warned that the flaw could compromise the integrity of forensic evidence and forensic DNA analysis.
The patch addresses the issue by tightening validation checks on the output files and ensuring that only authorized modifications are allowed.
Analysts noted that the flaw could have serious implications for forensic labs that rely on the software to generate evidence reports.
The vendor has urged all users of the affected software to apply the update immediately and to audit their current workflows for potential exploitation.
The update also includes guidance on how to verify the integrity of existing .fsa and .hid files.
Security experts have highlighted that the issue underscores the importance of robust file integrity checks in forensic software.
The patch is available for download from Thermo Fisher’s official support portal and is compatible with all recent releases of the Applied Biosystems suite.
Users are encouraged to follow the vendor’s instructions carefully and to keep their systems updated to prevent similar vulnerabilities in the future.