Description
There is a memory corruption vulnerability recently
discovered in NI LabVIEW that may result in information disclosure or arbitrary
code execution.  Successful exploitation requires an attacker to get a
user to open a specially crafted VI.  This vulnerability affects NI
LabVIEW 2026 Q3 (26.3.0) and prior versions.
Published: 2026-08-25
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

NI LabVIEW suffers an out‑of‑bounds read memory corruption when loading a VI. The vulnerability can cause sensitive data to be exposed or allow an attacker to execute arbitrary code. Successful exploitation requires an attacker to trick a user into opening a specially crafted VI file, after which the memory corruption occurs during the load process.

Affected Systems

The issue affects NI LabVIEW, specifically version 2026 Q3 (26.3.0) and all earlier releases.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability, and the EPSS score is not available, suggesting no publicly available exploitation count data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering step to have a user open a malicious VI; once that occurs the attack vector is local to the victim’s machine. Given the severe potential for arbitrary code execution, the risk remains high until the affected software is updated.

Generated by OpenCVE AI on August 25, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official NI security update or upgrade LabVIEW to a version released after 2026 Q3 that contains the fix.
  • In LabVIEW’s security settings, disable or restrict the ability to load external VI files if they are not required for normal operation.
  • Conduct targeted user education to prevent opening of unknown or untrusted VI files, and enforce file‑type and trust‑policy policies within your organization.

Generated by OpenCVE AI on August 25, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch7:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch8:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch9:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:-:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q3:*:*:*:*:*:*

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Title Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
First Time appeared Ni
Ni labview
Weaknesses CWE-125
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-26T03:56:27.848Z

Reserved: 2026-07-19T15:36:10.711Z

Link: CVE-2026-16234

cve-icon Vulnrichment

Updated: 2026-08-25T17:39:11.314Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:05.623

Modified: 2026-09-08T14:30:32.240

Link: CVE-2026-16234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:00:04Z

Weaknesses