Description
There is a memory corruption vulnerability recently
discovered in NI LabVIEW that may result in information disclosure or arbitrary
code execution.  Successful exploitation requires an attacker to get a
user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0)
and prior versions.
Published: 2026-08-25
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read vulnerability in NI LabVIEW allows an attacker to read memory beyond the intended buffer, which can lead to information disclosure or arbitrary code execution when a user opens a specially crafted VI file. This weakness, identified as CWE-125, compromises confidentiality and integrity of the system.

Affected Systems

NI LabVIEW version 2026 Q3 (26.3.0) and earlier releases.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and the exploit requires a user to open a malicious VI, suggesting a social-engineering vector. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, but the combination of a high CVSS score and user-action prerequisite still poses a significant risk to exposed installations.

Generated by OpenCVE AI on August 25, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest LabVIEW update released by NI to eliminate the out-of-bounds read flaw.
  • Restrict user access so that only trusted, signed VI files can be opened and warn users against opening unknown VI files.
  • Monitor system logs for anomalous memory corruption events or unauthorized LabVIEW usage to detect potential exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Title Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
First Time appeared Ni
Ni labview
Weaknesses CWE-125
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-25T17:43:24.098Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64202

cve-icon Vulnrichment

Updated: 2026-08-25T17:39:05.855Z

cve-icon NVD

Status : Received

Published: 2026-08-25T17:17:59.447

Modified: 2026-08-25T18:17:59.137

Link: CVE-2026-64202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:00:04Z

Weaknesses