Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-64202
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-64202 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to convince a user to open a specially crafted Virtual Instrument (VI) file. The vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, spanning multiple release branches back to at least 2022. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory). The vulnerability was published on August 25, 2026.

Technical details

The vulnerability is rooted in two memory safety weaknesses: CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), collectively classified under CAPEC-540 (Overread Buffers). When LabVIEW parses a maliciously crafted VI file, it fails to properly validate buffer boundaries, allowing reads or writes beyond allocated memory regions. The attack vector is local (the VI file must be opened by the victim), requires no privileges, and has low attack complexity — the primary precondition is user interaction (passive, i.e., opening a file). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, NI Advisory).

Impact

Successful exploitation can lead to arbitrary code execution with the privileges of the user running LabVIEW, unauthorized disclosure of sensitive information from process memory, or application crashes affecting availability. All three security pillars — confidentiality, integrity, and availability — are rated High impact on the vulnerable system, though subsequent/downstream systems are not directly impacted per the CVSS v4.0 assessment. In industrial and research environments where LabVIEW is commonly deployed, code execution could enable lateral movement or compromise of measurement and automation infrastructure (GitHub Advisory, NI Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.128% (3rd percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious VI file: Create a specially crafted NI LabVIEW Virtual Instrument (.vi) file that triggers out-of-bounds read or write conditions during parsing, exploiting the memory corruption flaw in LabVIEW's file handling routines.
  2. Deliver the file to the target: Distribute the malicious VI file via phishing email, shared network drives, collaboration platforms, or other social engineering channels commonly used in engineering and research environments where LabVIEW is deployed.
  3. Induce user interaction: Convince the target user to open the crafted VI file in LabVIEW. No elevated privileges or authentication are required on the attacker's part — only the victim's action of opening the file.
  4. Trigger memory corruption: Upon opening, LabVIEW processes the malformed file and performs an out-of-bounds read or write operation, corrupting process memory.
  5. Achieve code execution or information disclosure: Depending on the specific memory corruption primitive exploited, the attacker may achieve arbitrary code execution under the victim's user context, read sensitive data from process memory, or crash the application (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email, shared drives, or download directories; VI files with unusual metadata, oversized structures, or anomalous binary content.
  • Process: LabVIEW process (LabVIEW.exe or labview) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, bash, curl, wget); LabVIEW crashing unexpectedly or generating access violation / segmentation fault error logs.
  • Logs: Application crash reports or Windows Error Reporting (WER) entries referencing LabVIEW with memory access violations; system event logs showing abnormal LabVIEW termination.
  • Network: Outbound network connections from the LabVIEW process to unknown or unexpected external IP addresses following the opening of a VI file.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability across all affected branches: versions prior to 23.0.0 should upgrade to a supported branch; for the 23.x branch, upgrade to 23.3.10 or later; for the 24.x branch, upgrade to 24.3.7 or later; for the 25.x branch, upgrade to 25.3.5 or later; and for the 26.x branch, upgrade to 26.3.1 or later (NI Advisory). As a workaround, users should avoid opening VI files from untrusted or unknown sources. Organizations should implement file validation policies, user awareness training, and consider restricting LabVIEW's ability to open files from external or unverified locations.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64204HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64203HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64202HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64201HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-18445MEDIUM6.9
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management