CVE-2026-32860
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-32860 is a memory corruption vulnerability in NI LabVIEW caused by an out-of-bounds write when parsing LVLIB (LabVIEW Project Library) files. Successful exploitation requires a user to open a specially crafted .lvlib file, enabling arbitrary code execution or information disclosure in the context of the LabVIEW process. The vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, including the 2023, 2024, and 2025 release lines. It was published on April 7, 2026, with a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write): when LabVIEW parses a malformed or attacker-crafted LVLIB file, it fails to properly validate user-supplied data, allowing a write operation to occur beyond the bounds of an allocated buffer, resulting in memory corruption. The attack vector is local, requiring the target user to open a malicious .lvlib file (e.g., delivered via email, web download, or a malicious webpage), with no privileges required from the attacker. The Zero Day Initiative published an advisory (ZDI-26-290) describing the flaw, though no exploit code or reproduction steps were included (ZDI Advisory, GitHub Advisory).

Impact

Successful exploitation can result in arbitrary code execution or information disclosure within the context of the LabVIEW process, granting an attacker the same privileges as the running application. Given LabVIEW's common deployment in industrial, scientific, and engineering environments — including ICS/OT contexts — compromise could expose sensitive project data, measurement results, or control logic. Availability impact is also rated High, meaning a crafted file could crash the LabVIEW process entirely (GitHub Advisory, NI Advisory).

Exploitability

As of the time of reporting, no confirmed public exploit code is available; the ZDI advisory (ZDI-26-290) describes the vulnerability but does not include actionable attack artifacts (ZDI Advisory). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015–0.022%, placing it in a low percentile for near-term exploitation likelihood (GitHub Advisory).

Exploitation steps

  1. Craft a malicious LVLIB file: Create a specially crafted LabVIEW Project Library (.lvlib) file with malformed data designed to trigger an out-of-bounds write during parsing — for example, by manipulating length fields or data structures within the XML-based LVLIB format to cause a buffer overflow condition.
  2. Deliver the malicious file: Distribute the crafted .lvlib file to the target via phishing email, a malicious website offering a LabVIEW project download, or by embedding it in a shared project repository accessible to the victim.
  3. Induce user interaction: Social-engineer the target LabVIEW user into opening the malicious file, either by disguising it as a legitimate project library or by hosting it on a page that auto-triggers a file open dialog.
  4. Trigger memory corruption: When LabVIEW parses the malformed LVLIB file, the lack of input validation causes an out-of-bounds write, corrupting heap or stack memory in the LabVIEW process.
  5. Achieve code execution: With controlled memory corruption, an attacker can redirect execution flow to attacker-supplied shellcode or a ROP chain, executing arbitrary code with the privileges of the LabVIEW process (ZDI Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .lvlib files in LabVIEW project directories; newly created or modified files in the LabVIEW installation directory following a file open event.
  • Process: LabVIEW process (LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh); unusual network connections originating from the LabVIEW process.
  • Logs: Application crash logs or Windows Event Log entries indicating access violations or heap corruption in LabVIEW.exe; Windows Error Reporting (WER) entries referencing LabVIEW at the time of opening an LVLIB file.
  • Network: Outbound connections from the LabVIEW host to unknown external IPs shortly after a user opens an LVLIB file, potentially indicating a reverse shell or C2 beacon.

Mitigation and workarounds

NI has released patches addressing this vulnerability; users should update to the following fixed versions: LabVIEW 2023 Q3 Patch 9 (23.3.9) or later, LabVIEW 2024 Q3 Patch 6 (24.3.6) or later, LabVIEW 2025 Q3 Patch 4 (25.3.4) or later, and LabVIEW 2026 Q1 Patch 1 (26.1.1) or later (NI Advisory). Until patching is possible, organizations should restrict users from opening LVLIB files from untrusted sources, implement file-type filtering at email gateways and web proxies, and avoid opening LabVIEW projects received from unknown parties. In ICS/OT environments, consider network segmentation to limit the blast radius of any potential compromise.

Community reactions

The vulnerability was noted in a CISA weekly vulnerability bulletin (SB26-103) covering the week of April 6, 2026, indicating it received standard government tracking (CISA Bulletin). It was also covered in ICS-focused security blogs, including a review of public ICS disclosures for the week of April 4, 2026 (ICS Security Blog). Social media mentions were limited to automated CVE notification accounts on Bluesky and Mastodon, with no significant researcher commentary or broader community discussion observed.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-32864HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32863HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32862HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32861HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32860HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management