
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64202 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to convince a user to open a specially crafted Virtual Instrument (VI) file. The vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, spanning multiple release branches back to at least 2022. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory). The vulnerability was published on August 25, 2026.
The vulnerability is rooted in two memory safety weaknesses: CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), collectively classified under CAPEC-540 (Overread Buffers). When LabVIEW parses a maliciously crafted VI file, it fails to properly validate buffer boundaries, allowing reads or writes beyond allocated memory regions. The attack vector is local (the VI file must be opened by the victim), requires no privileges, and has low attack complexity — the primary precondition is user interaction (passive, i.e., opening a file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, NI Advisory).
Successful exploitation can lead to arbitrary code execution with the privileges of the user running LabVIEW, unauthorized disclosure of sensitive information from process memory, or application crashes affecting availability. All three security pillars — confidentiality, integrity, and availability — are rated High impact on the vulnerable system, though subsequent/downstream systems are not directly impacted per the CVSS v4.0 assessment. In industrial and research environments where LabVIEW is commonly deployed, code execution could enable lateral movement or compromise of measurement and automation infrastructure (GitHub Advisory, NI Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.128% (3rd percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
.vi files received via email, shared drives, or download directories; VI files with unusual metadata, oversized structures, or anomalous binary content.LabVIEW.exe or labview) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, bash, curl, wget); LabVIEW crashing unexpectedly or generating access violation / segmentation fault error logs.NI has released patched versions addressing this vulnerability across all affected branches: versions prior to 23.0.0 should upgrade to a supported branch; for the 23.x branch, upgrade to 23.3.10 or later; for the 24.x branch, upgrade to 24.3.7 or later; for the 25.x branch, upgrade to 25.3.5 or later; and for the 26.x branch, upgrade to 26.3.1 or later (NI Advisory). As a workaround, users should avoid opening VI files from untrusted or unknown sources. Organizations should implement file validation policies, user awareness training, and consider restricting LabVIEW's ability to open files from external or unverified locations.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."