Description
There is a memory corruption vulnerability recently
discovered in NI LabVIEW that may result in information disclosure or arbitrary
code execution.  Successful exploitation requires an attacker to get a
user to open a specially crafted VI.  This vulnerability affects NI
LabVIEW 2026 Q3 (26.3.0) and prior versions.
Published: 2026-08-25
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Immediate Patch
AI Analysis

Impact

A memory corruption vulnerability in NI LabVIEW can allow an attacker to read beyond array bounds when loading a specially crafted VI, potentially leading to information disclosure or arbitrary code execution. The weakness is a classic out-of-bounds read (CWE-125) that can compromise the confidentiality, integrity and availability of a system.

Affected Systems

NI LabVIEW versions 2026 Q3 (26.3.0) and all earlier releases are affected. The vulnerability applies to the standard NI LabVIEW product.

Risk and Exploitability

The CVSS score of 8.5 classifies the flaw as high severity, and the EPSS score of < 1% indicates a low but non‑zero exploitation probability. The lack of a KEV listing does not diminish the risk of exploitation. Due to the local user interaction requirement, the attack vector is inferred as a social engineering or phishing scenario where a user must intentionally open a malicious VI file. Once executed, the exploit could allow full code execution under the context of the current user.

Generated by OpenCVE AI on September 3, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest LabVIEW security update released by NI that fixes the memory corruption vulnerability. The update can be obtained from NI’s official support site.
  • Upgrade all LabVIEW installations to a version newer than 2026 Q3 (for example, 2026 Q4 or later) where the vulnerability is resolved.
  • Restrict the ability of untrusted users to open VI files by removing network shares that expose LabVIEW projects, applying strict file‑system permissions, and disabling auto-load features for external VI files.

Generated by OpenCVE AI on September 3, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CPEs cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch7:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch8:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2023:q3_patch9:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:-:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch5:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2024:q3_patch6:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q1_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch3:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2025:q3_patch4:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch1:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q1_patch2:*:*:*:*:*:*
cpe:2.3:a:ni:labview:2026:q3:*:*:*:*:*:*

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Title Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
First Time appeared Ni
Ni labview
Weaknesses CWE-125
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-26T03:56:31.817Z

Reserved: 2026-07-19T15:12:06.826Z

Link: CVE-2026-64203

cve-icon Vulnrichment

Updated: 2026-08-25T17:39:00.835Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:59.587

Modified: 2026-09-03T15:00:30.377

Link: CVE-2026-64203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T18:15:04Z

Weaknesses