
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18445 is an integer overflow vulnerability (CWE-190) in NI LabVIEW that results in an out-of-bounds write, potentially leading to information disclosure or arbitrary code execution. It was published on August 25, 2026, and affects NI LabVIEW 2026 Q3 and all prior versions, including version lines 23.x (before 23.3.10), 24.x (before 24.3.7), 25.x (before 25.3.5), 26.x (before 26.3.1), and all versions prior to 23.0.0. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, NI Advisory).
The root cause is an integer overflow or wraparound (CWE-190) in NI LabVIEW's VI file parsing logic, where a calculation produces a value too large for its associated integer representation, causing a subsequent out-of-bounds write to memory. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted VI (Virtual Instrument) file supplied by the attacker. The out-of-bounds write condition can corrupt adjacent memory regions, enabling an attacker to influence program control flow and potentially achieve arbitrary code execution with the privileges of the user running LabVIEW (GitHub Advisory, NI Advisory). No public proof-of-concept code has been identified at this time (GitHub Advisory).
Successful exploitation can result in information disclosure from memory or arbitrary code execution with the privileges of the user running LabVIEW, impacting confidentiality, integrity, and availability of the affected system. Because LabVIEW is widely used in industrial, scientific, and engineering environments — including critical infrastructure — compromise of a workstation running LabVIEW could expose sensitive operational data or allow an attacker to manipulate instrumentation and control workflows. Lateral movement potential depends on the network posture of the affected host, but code execution under the user's context could enable credential harvesting or further pivoting within an engineering network (GitHub Advisory, NI Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.122% (2nd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). Exploitation is not automatable, as it requires user interaction to open a malicious VI file, limiting the attack surface to social engineering scenarios.
.vi or .llb files received via email, file shares, or removable media; newly created or modified files in LabVIEW project directories following file open events.LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, curl, wget) or making unusual network connections after opening a VI file; application crashes or abnormal termination of LabVIEW following file open events.LabVIEW.exe; security logs indicating new process creation under the LabVIEW process context.NI has released patched versions addressing this vulnerability: users should upgrade to LabVIEW 23.3.10 or later (for the 23.x line), 24.3.7 or later (for the 24.x line), 25.3.5 or later (for the 25.x line), or 26.3.1 or later (for the 26.x line) (NI Advisory). As interim mitigations, users should exercise caution when opening VI files from untrusted or unverified sources, and organizations should consider restricting user permissions and implementing application whitelisting to limit the impact of potential code execution. Disabling the automatic opening of VI files from email attachments or external media can further reduce exposure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."