Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-64201
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-64201 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. It affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, including all releases from 2022 and earlier, as well as specific quarterly releases in the 2023–2026 range. The vulnerability was published on August 25, 2026, with a patch advisory added by NI shortly thereafter. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).

Technical details

The vulnerability is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), indicating improper bounds checking during memory operations when parsing LabVIEW VI files. Exploitation is local in attack vector and requires no privileges, but does require user interaction — specifically, a victim must be socially engineered into opening a specially crafted VI (Virtual Instrument) file. The attack complexity is low, meaning no special conditions or bypass techniques are needed beyond delivering the malicious file. No public proof-of-concept code has been identified at this time (GitHub Advisory, NI Advisory).

Impact

Successful exploitation can lead to arbitrary code execution with the privileges of the user running LabVIEW, or disclosure of sensitive information from the application's memory. The impact on confidentiality, integrity, and availability of the vulnerable system is rated High across all three dimensions. Because LabVIEW is widely used in industrial, scientific, and engineering environments — including critical infrastructure — exploitation could have significant downstream consequences depending on the deployment context (GitHub Advisory, NI Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.128% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Craft a malicious VI file: Create a specially crafted LabVIEW Virtual Instrument (.vi) file that triggers an out-of-bounds read or write during parsing, exploiting improper memory bounds checking in vulnerable LabVIEW versions (≤26.3.0).
  2. Deliver the payload: Distribute the malicious VI file to a target user via phishing email, file-sharing platform, or other social engineering methods, disguising it as a legitimate LabVIEW project or instrument file.
  3. Induce user interaction: Convince the target to open the crafted VI file using a vulnerable version of NI LabVIEW (any version prior to the patched releases: 23.3.10, 24.3.7, 25.3.5, or 26.3.1).
  4. Trigger memory corruption: Upon opening, LabVIEW processes the malformed VI file, triggering the out-of-bounds read/write condition in memory.
  5. Achieve code execution or data disclosure: Depending on the specific memory corruption primitive exploited, the attacker may achieve arbitrary code execution with the privileges of the LabVIEW process, or read sensitive data from application memory (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email, downloads, or shared drives; VI files with unusual metadata, oversized structures, or anomalous binary content.
  • Process: LabVIEW process (LabVIEW.exe or equivalent) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh, curl) or crashing unexpectedly upon opening a specific file.
  • Logs: Application crash logs or Windows Event Logs showing access violations or memory exceptions originating from the LabVIEW process; Dr. Watson or Windows Error Reporting entries tied to LabVIEW.
  • Network: Unexpected outbound network connections from the LabVIEW process to external IP addresses following the opening of a VI file, which may indicate a post-exploitation callback or data exfiltration attempt.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability. Users should upgrade to the following fixed versions or later: 23.3.10 (for 2023 Q3 branch), 24.3.7 (for 2024 Q3 branch), 25.3.5 (for 2025 Q3 branch), or 26.3.1 (for 2026 Q3 branch). As an interim workaround, users should avoid opening VI files from untrusted or unknown sources, implement user awareness training to recognize suspicious file attachments, and consider restricting LabVIEW file access through endpoint controls where feasible (NI Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64204HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64203HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64202HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64201HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-18445MEDIUM6.9
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management