
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32860 is a memory corruption vulnerability in NI LabVIEW caused by an out-of-bounds write when parsing LVLIB (LabVIEW Project Library) files. Successful exploitation requires a user to open a specially crafted .lvlib file, enabling arbitrary code execution or information disclosure in the context of the LabVIEW process. The vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, including the 2023, 2024, and 2025 release lines. It was published on April 7, 2026, with a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write): when LabVIEW parses a malformed or attacker-crafted LVLIB file, it fails to properly validate user-supplied data, allowing a write operation to occur beyond the bounds of an allocated buffer, resulting in memory corruption. The attack vector is local, requiring the target user to open a malicious .lvlib file (e.g., delivered via email, web download, or a malicious webpage), with no privileges required from the attacker. The Zero Day Initiative published an advisory (ZDI-26-290) describing the flaw, though no exploit code or reproduction steps were included (ZDI Advisory, GitHub Advisory).
Successful exploitation can result in arbitrary code execution or information disclosure within the context of the LabVIEW process, granting an attacker the same privileges as the running application. Given LabVIEW's common deployment in industrial, scientific, and engineering environments — including ICS/OT contexts — compromise could expose sensitive project data, measurement results, or control logic. Availability impact is also rated High, meaning a crafted file could crash the LabVIEW process entirely (GitHub Advisory, NI Advisory).
As of the time of reporting, no confirmed public exploit code is available; the ZDI advisory (ZDI-26-290) describes the vulnerability but does not include actionable attack artifacts (ZDI Advisory). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015–0.022%, placing it in a low percentile for near-term exploitation likelihood (GitHub Advisory).
.lvlib) file with malformed data designed to trigger an out-of-bounds write during parsing — for example, by manipulating length fields or data structures within the XML-based LVLIB format to cause a buffer overflow condition..lvlib file to the target via phishing email, a malicious website offering a LabVIEW project download, or by embedding it in a shared project repository accessible to the victim..lvlib files in LabVIEW project directories; newly created or modified files in the LabVIEW installation directory following a file open event.LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh); unusual network connections originating from the LabVIEW process.LabVIEW.exe; Windows Error Reporting (WER) entries referencing LabVIEW at the time of opening an LVLIB file.NI has released patches addressing this vulnerability; users should update to the following fixed versions: LabVIEW 2023 Q3 Patch 9 (23.3.9) or later, LabVIEW 2024 Q3 Patch 6 (24.3.6) or later, LabVIEW 2025 Q3 Patch 4 (25.3.4) or later, and LabVIEW 2026 Q1 Patch 1 (26.1.1) or later (NI Advisory). Until patching is possible, organizations should restrict users from opening LVLIB files from untrusted sources, implement file-type filtering at email gateways and web proxies, and avoid opening LabVIEW projects received from unknown parties. In ICS/OT environments, consider network segmentation to limit the blast radius of any potential compromise.
The vulnerability was noted in a CISA weekly vulnerability bulletin (SB26-103) covering the week of April 6, 2026, indicating it received standard government tracking (CISA Bulletin). It was also covered in ICS-focused security blogs, including a review of public ICS disclosures for the week of April 4, 2026 (ICS Security Blog). Social media mentions were limited to automated CVE notification accounts on Bluesky and Mastodon, with no significant researcher commentary or broader community discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."