Impact
NI LabVIEW is vulnerable to an out‑of‑bounds read that can corrupt memory when a victim opens a specially crafted VI. The flaw can expose sensitive information or allow an attacker to execute arbitrary code on the compromised machine, as the exploited memory corruption is not confined to read‑only data.
Affected Systems
The vulnerability applies to NI LabVIEW versions 2026 Q3 (26.3.0) and all earlier releases. Users running any of these versions are at risk unless the software is upgraded to a fixed release.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity risk, and the EPSS score of 0.00128 (just under 1%) reflects a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to open a malicious VI file; thus the attack vector is most likely local or through social engineering, though any method that delivers the crafted VI can lead to successful exploitation.
OpenCVE Enrichment