Impact
NI LabVIEW suffers an out‑of‑bounds read memory corruption when loading a VI. The vulnerability can cause sensitive data to be exposed or allow an attacker to execute arbitrary code. Successful exploitation requires an attacker to trick a user into opening a specially crafted VI file, after which the memory corruption occurs during the load process.
Affected Systems
The issue affects NI LabVIEW, specifically version 2026 Q3 (26.3.0) and all earlier releases.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, and the EPSS score is not available, suggesting no publicly available exploitation count data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering step to have a user open a malicious VI; once that occurs the attack vector is local to the victim’s machine. Given the severe potential for arbitrary code execution, the risk remains high until the affected software is updated.
OpenCVE Enrichment