The break here is evidentiary, not operational. If someone can change a lab-controlled .fsa or .hid file before analysis, the software may accept a compromised record as normal and the casework becomes harder to defend after the fact.
Thermo Fisher patched CVE-2026-17583 in five supported Applied Biosystems human identification product lines by adding digital signatures. The affected software includes 3500/3500xL Series Data Collection Software, 3730/3730xL Series Data Collection Software, SeqStudio Genetic Analyzer Data Collection Software, SeqStudio Flex Series Instrument Software, and GeneMapper ID-X Software; three end-of-life data collection lines remain without a vendor fix.
That leaves stored forensic DNA outputs as a custody problem, not just a patch problem. Labs using the unpatched EOL lines have to treat file handling, access, privilege, and network controls as part of evidence integrity, because the original analysis record may no longer be straightforward to authenticate.