CVE-2026-32864
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-32864 is a memory corruption vulnerability caused by an out-of-bounds read in the mgcore_SH_25_3!aligned_free() function in NI LabVIEW. Successful exploitation can result in information disclosure or arbitrary code execution, requiring an attacker to socially engineer a user into opening a specially crafted VI file. The vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, including versions prior to 23.0.0, 23.1.0–23.3.8, 24.1.0–24.3.5, and 25.1.0–25.3.3. It was published on April 7, 2026, with patches released the same day. The CVSS v4.0 base score is 8.5 (High) (GitHub Advisory, NI Advisory).

Technical details

The root cause is an out-of-bounds read (CWE-125) in the mgcore_SH_25_3!aligned_free() function within NI LabVIEW's core library, which constitutes a memory corruption condition. When a user opens a specially crafted LabVIEW VI (Virtual Instrument) file, the application reads memory beyond the intended buffer boundary, potentially exposing sensitive memory contents or corrupting memory in a way that enables code execution. The attack vector is local, requires no privileges, but does require passive user interaction (opening a malicious file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, NI Advisory).

Impact

Successful exploitation can result in high confidentiality, integrity, and availability impacts on the vulnerable system. An attacker could read sensitive data from process memory (information disclosure) or achieve arbitrary code execution with the privileges of the user running LabVIEW, potentially enabling further lateral movement within engineering or industrial control system environments where LabVIEW is commonly deployed. The scope is limited to the vulnerable system itself, with no direct impact on subsequent systems, though code execution could serve as a foothold for broader compromise (GitHub Advisory, NI Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015–0.018%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported. Exploitation requires user interaction, which reduces the likelihood of opportunistic mass exploitation but does not eliminate targeted attack risk, particularly in industrial and research environments where LabVIEW is widely used.

Exploitation steps

  1. Craft a malicious VI file: Create a specially crafted LabVIEW Virtual Instrument (.vi) file that triggers the out-of-bounds read in mgcore_SH_25_3!aligned_free() when parsed by LabVIEW.
  2. Deliver the file to the target: Use social engineering techniques such as phishing emails, malicious downloads, or shared network drives to deliver the crafted VI file to a user running a vulnerable version of NI LabVIEW (2026 Q1 / 26.1.0 or earlier).
  3. Induce user interaction: Convince the target user to open the malicious VI file within LabVIEW, which triggers the vulnerable code path during file parsing.
  4. Trigger memory corruption: The out-of-bounds read in aligned_free() is triggered, causing memory corruption that may expose sensitive memory contents or allow control of execution flow.
  5. Achieve objective: Depending on exploit reliability and memory layout, the attacker may achieve information disclosure (reading sensitive data from process memory) or arbitrary code execution with the privileges of the LabVIEW user process (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email, shared drives, or downloads from untrusted sources; VI files with unusual metadata or originating from unknown parties.
  • Process: LabVIEW process (LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, network utilities); LabVIEW crashing or generating access violation errors when opening specific VI files.
  • Logs: Application crash logs or Windows Event Logs referencing faults in mgcore_SH_25_3.dll or aligned_free(); Dr. Watson / Windows Error Reporting entries associated with LabVIEW memory access violations.
  • Network: Unexpected outbound network connections from the LabVIEW process to external IP addresses following the opening of a VI file.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability: LabVIEW 23.3.9 or later, 24.3.6 or later, 25.3.4 or later, and 26.1.1 or later. Users should upgrade to the appropriate patched version immediately (NI Advisory). As a workaround, organizations should train users not to open VI files from untrusted or unknown sources, implement file execution policies to restrict unauthorized VI file execution, and monitor for suspicious VI file activity. Given the high severity (CVSS 8.5) and potential for arbitrary code execution, prompt patching is strongly recommended.

Community reactions

The vulnerability was noted in ICS-focused security community blogs, including a weekly public ICS disclosure review (ICS Security Blog). Automated CVE tracking accounts on Bluesky and aggregator sites such as VulDB and The Hacker Wire picked up the disclosure shortly after publication. No significant vendor statements beyond the NI security advisory, nor notable independent researcher commentary, have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-32864HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32863HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32862HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32861HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32860HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management