
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32864 is a memory corruption vulnerability caused by an out-of-bounds read in the mgcore_SH_25_3!aligned_free() function in NI LabVIEW. Successful exploitation can result in information disclosure or arbitrary code execution, requiring an attacker to socially engineer a user into opening a specially crafted VI file. The vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, including versions prior to 23.0.0, 23.1.0–23.3.8, 24.1.0–24.3.5, and 25.1.0–25.3.3. It was published on April 7, 2026, with patches released the same day. The CVSS v4.0 base score is 8.5 (High) (GitHub Advisory, NI Advisory).
The root cause is an out-of-bounds read (CWE-125) in the mgcore_SH_25_3!aligned_free() function within NI LabVIEW's core library, which constitutes a memory corruption condition. When a user opens a specially crafted LabVIEW VI (Virtual Instrument) file, the application reads memory beyond the intended buffer boundary, potentially exposing sensitive memory contents or corrupting memory in a way that enables code execution. The attack vector is local, requires no privileges, but does require passive user interaction (opening a malicious file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, NI Advisory).
Successful exploitation can result in high confidentiality, integrity, and availability impacts on the vulnerable system. An attacker could read sensitive data from process memory (information disclosure) or achieve arbitrary code execution with the privileges of the user running LabVIEW, potentially enabling further lateral movement within engineering or industrial control system environments where LabVIEW is commonly deployed. The scope is limited to the vulnerable system itself, with no direct impact on subsequent systems, though code execution could serve as a foothold for broader compromise (GitHub Advisory, NI Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015–0.018%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported. Exploitation requires user interaction, which reduces the likelihood of opportunistic mass exploitation but does not eliminate targeted attack risk, particularly in industrial and research environments where LabVIEW is widely used.
mgcore_SH_25_3!aligned_free() when parsed by LabVIEW.aligned_free() is triggered, causing memory corruption that may expose sensitive memory contents or allow control of execution flow..vi files received via email, shared drives, or downloads from untrusted sources; VI files with unusual metadata or originating from unknown parties.LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, network utilities); LabVIEW crashing or generating access violation errors when opening specific VI files.mgcore_SH_25_3.dll or aligned_free(); Dr. Watson / Windows Error Reporting entries associated with LabVIEW memory access violations.NI has released patched versions addressing this vulnerability: LabVIEW 23.3.9 or later, 24.3.6 or later, 25.3.4 or later, and 26.1.1 or later. Users should upgrade to the appropriate patched version immediately (NI Advisory). As a workaround, organizations should train users not to open VI files from untrusted or unknown sources, implement file execution policies to restrict unauthorized VI file execution, and monitor for suspicious VI file activity. Given the high severity (CVSS 8.5) and potential for arbitrary code execution, prompt patching is strongly recommended.
The vulnerability was noted in ICS-focused security community blogs, including a weekly public ICS disclosure review (ICS Security Blog). Automated CVE tracking accounts on Bluesky and aggregator sites such as VulDB and The Hacker Wire picked up the disclosure shortly after publication. No significant vendor statements beyond the NI security advisory, nor notable independent researcher commentary, have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."