Description
There is a memory corruption vulnerability recently
discovered in NI LabVIEW that may result in information disclosure or arbitrary
code execution.  Successful exploitation requires an attacker to get a
user to open a specially crafted VI.  This vulnerability affects NI
LabVIEW 2026 Q3 (26.3.0) and prior versions.
Published: 2026-08-25
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a memory corruption flaw caused by an out-of-bounds write in NI LabVIEW when a user loads a VI. According to the description, this flaw can lead to information disclosure or arbitrary code execution, which is consistent with the CWE-787 classification.

Affected Systems

NI LabVIEW 2026 Q3 (build 26.3.0) and all earlier releases are affected. The flaw is present in all known NI LabVIEW products that include the VI loader.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity level. There is no EPSS score available, so the precise exploitation likelihood is unknown, but the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation requires a user to open a specially crafted VI, so the attack vector is local user interaction, possibly via phishing or social engineering.

Generated by OpenCVE AI on August 25, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official LabVIEW security update released by NI that addresses the out‑of‑bounds write flaw.
  • Ensure all installations of LabVIEW are upgraded to a patched version that is newer than 2026 Q3 (26.3.0).
  • Restrict user access so that only trusted and validated VI files can be opened, and provide training to users about the risks of opening unknown VI files.

Generated by OpenCVE AI on August 25, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Title Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
First Time appeared Ni
Ni labview
Weaknesses CWE-787
CPEs cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Vendors & Products Ni
Ni labview
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-08-25T17:43:23.755Z

Reserved: 2026-07-19T15:12:06.826Z

Link: CVE-2026-64204

cve-icon Vulnrichment

Updated: 2026-08-25T17:38:58.500Z

cve-icon NVD

Status : Received

Published: 2026-08-25T17:17:59.727

Modified: 2026-08-25T18:17:59.653

Link: CVE-2026-64204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:00:04Z

Weaknesses