Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-18445
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-18445 is an integer overflow vulnerability (CWE-190) in NI LabVIEW that results in an out-of-bounds write, potentially leading to information disclosure or arbitrary code execution. It was published on August 25, 2026, and affects NI LabVIEW 2026 Q3 and all prior versions, including version lines 23.x (before 23.3.10), 24.x (before 24.3.7), 25.x (before 25.3.5), 26.x (before 26.3.1), and all versions prior to 23.0.0. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, NI Advisory).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in NI LabVIEW's VI file parsing logic, where a calculation produces a value too large for its associated integer representation, causing a subsequent out-of-bounds write to memory. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted VI (Virtual Instrument) file supplied by the attacker. The out-of-bounds write condition can corrupt adjacent memory regions, enabling an attacker to influence program control flow and potentially achieve arbitrary code execution with the privileges of the user running LabVIEW (GitHub Advisory, NI Advisory). No public proof-of-concept code has been identified at this time (GitHub Advisory).

Impact

Successful exploitation can result in information disclosure from memory or arbitrary code execution with the privileges of the user running LabVIEW, impacting confidentiality, integrity, and availability of the affected system. Because LabVIEW is widely used in industrial, scientific, and engineering environments — including critical infrastructure — compromise of a workstation running LabVIEW could expose sensitive operational data or allow an attacker to manipulate instrumentation and control workflows. Lateral movement potential depends on the network posture of the affected host, but code execution under the user's context could enable credential harvesting or further pivoting within an engineering network (GitHub Advisory, NI Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.122% (2nd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). Exploitation is not automatable, as it requires user interaction to open a malicious VI file, limiting the attack surface to social engineering scenarios.

Exploitation steps

  1. Craft a malicious VI file: The attacker creates a specially crafted NI LabVIEW VI file that contains malformed data designed to trigger an integer overflow during parsing — for example, by embedding a field with an oversized length value that, when processed, wraps around and causes an out-of-bounds write.
  2. Deliver the file to the target: The attacker distributes the malicious VI file via phishing email, a compromised file-sharing platform, a USB drive, or by posing as a legitimate LabVIEW project or instrument driver.
  3. Social engineer the victim: The attacker convinces the target user (e.g., an engineer or researcher) to open the VI file in NI LabVIEW, exploiting the trust users typically place in VI files shared within their professional community.
  4. Trigger the vulnerability: When the victim opens the file, LabVIEW's VI parser processes the malformed data, causing an integer overflow that results in an out-of-bounds write to memory.
  5. Achieve code execution or information disclosure: Depending on the memory layout and exploit precision, the attacker may achieve arbitrary code execution with the privileges of the LabVIEW user, or extract sensitive information from adjacent memory regions (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi or .llb files received via email, file shares, or removable media; newly created or modified files in LabVIEW project directories following file open events.
  • Process: LabVIEW process (LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, curl, wget) or making unusual network connections after opening a VI file; application crashes or abnormal termination of LabVIEW following file open events.
  • Logs: Windows Event Logs showing application crashes (Event ID 1000/1001) associated with LabVIEW.exe; security logs indicating new process creation under the LabVIEW process context.
  • Network: Outbound connections from the LabVIEW host to unknown or suspicious IP addresses or domains shortly after a VI file is opened, which may indicate a successful payload execution or C2 callback.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability: users should upgrade to LabVIEW 23.3.10 or later (for the 23.x line), 24.3.7 or later (for the 24.x line), 25.3.5 or later (for the 25.x line), or 26.3.1 or later (for the 26.x line) (NI Advisory). As interim mitigations, users should exercise caution when opening VI files from untrusted or unverified sources, and organizations should consider restricting user permissions and implementing application whitelisting to limit the impact of potential code execution. Disabling the automatic opening of VI files from email attachments or external media can further reduce exposure.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64204HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64203HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64202HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64201HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-18445MEDIUM6.9
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management