Description
There is a memory corruption vulnerability recently
discovered in NI LabVIEW that may result in information disclosure or arbitrary
code execution.  Successful exploitation requires an attacker to get a
user to open a specially crafted VI.  This vulnerability affects NI
LabVIEW 2026 Q3 (26.3.0) and prior versions.
Published: 2026-08-25
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NI LabVIEW contains an out‑of‑bounds write that can corrupt memory. An attacker can craft a VI file that, when opened by a user, triggers the corruption. This may lead to disclosure of sensitive data or execution of arbitrary code, impacting the confidentiality and integrity of the system.

Affected Systems

The vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and all earlier releases. Systems running any of these versions are potentially vulnerable until a patch or newer version is applied.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, but the EPSS score is not available, so widespread exploitation probability is unclear. The vulnerability is currently not listed in the CISA KEV catalog. Attack requires a user to open a malicious VI file, so the attack vector is local user interaction. Exploitation would require the attacker to supply or convince a user to load a crafted VI onto the target system.

Generated by OpenCVE AI on August 25, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest LabVIEW update from NI that addresses the memory corruption flaw
  • Upgrade to LabVIEW 2026 Q3 (26.3.0) or newer if your system is running an older release
  • Restrict or disable loading of VI files from untrusted or unknown sources

Generated by OpenCVE AI on August 25, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Title Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
First Time appeared Ni
Ni labview
Weaknesses CWE-787
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-25T17:43:24.612Z

Reserved: 2026-07-19T15:36:09.751Z

Link: CVE-2026-16233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T17:17:05.447

Modified: 2026-08-25T17:17:05.447

Link: CVE-2026-16233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T17:30:07Z

Weaknesses