CVE-2026-32862
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-32862 is a memory corruption vulnerability caused by an out-of-bounds write in the ResFileFactory::InitResourceMgr() function of NI LabVIEW. Successful exploitation can result in information disclosure or arbitrary code execution on the affected system. The vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, including versions through 23.x, 24.x, and 25.x release lines. It was published on April 7, 2026, with patches made available shortly after. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).

Technical details

The root cause is an out-of-bounds write (CWE-787) in the ResFileFactory::InitResourceMgr() function within NI LabVIEW's resource file parsing logic. When LabVIEW processes a specially crafted VI (Virtual Instrument) file, insufficient bounds checking allows data to be written beyond the intended buffer boundary, corrupting adjacent memory. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a user must be socially engineered into opening a malicious .vi file. No public proof-of-concept code has been identified at this time (GitHub Advisory, NI Advisory).

Impact

Successful exploitation grants an attacker arbitrary code execution on the victim's system with the privileges of the user running LabVIEW, resulting in high confidentiality, integrity, and availability impact. An attacker could exfiltrate sensitive data, modify system files, or cause a denial of service. Given that LabVIEW is widely used in industrial, scientific, and engineering environments — including ICS/OT contexts — exploitation could have significant downstream consequences for critical infrastructure or research systems (GitHub Advisory, NI Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (NI Advisory). The EPSS score is approximately 0.015% (0.022% per GitHub Advisory), placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Craft a malicious VI file: Create a specially crafted LabVIEW Virtual Instrument (.vi) file that contains malformed resource data designed to trigger the out-of-bounds write in ResFileFactory::InitResourceMgr() during file parsing.
  2. Deliver the file to the target: Use social engineering techniques such as phishing emails, malicious downloads, or shared network drives to deliver the crafted .vi file to a user who has NI LabVIEW installed.
  3. Induce the user to open the file: Convince the target user to open the malicious .vi file using LabVIEW, for example by disguising it as a legitimate instrument or project file.
  4. Trigger memory corruption: Upon opening, LabVIEW's resource manager parses the file and the out-of-bounds write corrupts adjacent memory, potentially overwriting function pointers or control flow data.
  5. Achieve code execution: Depending on the memory layout and exploit reliability, the attacker achieves arbitrary code execution with the privileges of the LabVIEW process, enabling further actions such as persistence, data exfiltration, or lateral movement (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email attachments, file shares, or downloads from untrusted sources; new executable files or scripts created in LabVIEW installation directories or user temp folders following a VI file open event.
  • Process: Unusual child processes spawned by the LabVIEW process (e.g., cmd.exe, powershell.exe, bash, curl, or network utilities); LabVIEW process crashing or exhibiting abnormal behavior after opening a VI file.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing LabVIEW with faulting module related to resource file parsing; unexpected process creation events logged by EDR solutions originating from the LabVIEW executable.
  • Network: Outbound network connections from the LabVIEW process to unknown or suspicious external IP addresses following a file open event, which may indicate a reverse shell or data exfiltration attempt.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability. Users should upgrade to the following fixed releases based on their current version branch: NI LabVIEW 26.1.1 or later (for 26.1.0), 24.3.6 or later (for 24.x), 25.3.4 or later (for 25.x), and 23.3.9 or later (for 23.x) (NI Advisory). As interim mitigations, organizations should restrict users from opening VI files from untrusted or unknown sources, implement user awareness training around suspicious file attachments, and consider disabling LabVIEW in environments where it is not strictly necessary until patching is complete.

Community reactions

The vulnerability received brief coverage on security-focused social media, including a mention on Mastodon via The Hacker Wire shortly after disclosure. It was also noted in a weekly ICS security disclosure review blog, reflecting its relevance to industrial control system environments where LabVIEW is commonly deployed (Chemical Facility Security News). Tenable added detection coverage for the vulnerability in their plugin pipeline. No major vendor statements beyond NI's own advisory or significant researcher commentary have been publicly identified.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-32864HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32863HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32862HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32861HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32860HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management