
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64201 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. It affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, including all releases from 2022 and earlier, as well as specific quarterly releases in the 2023–2026 range. The vulnerability was published on August 25, 2026, with a patch advisory added by NI shortly thereafter. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).
The vulnerability is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), indicating improper bounds checking during memory operations when parsing LabVIEW VI files. Exploitation is local in attack vector and requires no privileges, but does require user interaction — specifically, a victim must be socially engineered into opening a specially crafted VI (Virtual Instrument) file. The attack complexity is low, meaning no special conditions or bypass techniques are needed beyond delivering the malicious file. No public proof-of-concept code has been identified at this time (GitHub Advisory, NI Advisory).
Successful exploitation can lead to arbitrary code execution with the privileges of the user running LabVIEW, or disclosure of sensitive information from the application's memory. The impact on confidentiality, integrity, and availability of the vulnerable system is rated High across all three dimensions. Because LabVIEW is widely used in industrial, scientific, and engineering environments — including critical infrastructure — exploitation could have significant downstream consequences depending on the deployment context (GitHub Advisory, NI Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.128% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
.vi files received via email, downloads, or shared drives; VI files with unusual metadata, oversized structures, or anomalous binary content.LabVIEW.exe or equivalent) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh, curl) or crashing unexpectedly upon opening a specific file.NI has released patched versions addressing this vulnerability. Users should upgrade to the following fixed versions or later: 23.3.10 (for 2023 Q3 branch), 24.3.7 (for 2024 Q3 branch), 25.3.5 (for 2025 Q3 branch), or 26.3.1 (for 2026 Q3 branch). As an interim workaround, users should avoid opening VI files from untrusted or unknown sources, implement user awareness training to recognize suspicious file attachments, and consider restricting LabVIEW file access through endpoint controls where feasible (NI Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."