
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64203 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. Disclosed on August 25, 2026, it affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, specifically versions below 23.0.0, 23.1.0–23.3.10, 24.1.0–24.3.7, 25.1.0–25.3.5, and 26.1.0–26.3.1. Successful exploitation requires a user to open a specially crafted Virtual Instrument (VI) file. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).
The vulnerability is rooted in improper memory handling within NI LabVIEW's VI file parsing logic, classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker crafts a malicious VI file that, when opened by a victim, triggers out-of-bounds memory read or write operations, potentially corrupting process memory. The attack vector is local (the file must be opened on the target system), requires no privileges, and has low attack complexity — the primary precondition is user interaction (passive; the user must open the file). No public proof-of-concept code has been identified at this time (GitHub Advisory, NI Advisory).
Successful exploitation can lead to arbitrary code execution or sensitive information disclosure, with high impact to confidentiality, integrity, and availability of the affected system. Code execution would occur with the privileges of the user running LabVIEW, which in industrial or engineering environments may include access to sensitive measurement data, test configurations, or control system interfaces. Lateral movement potential depends on the victim's network access and privilege level, but the scope is limited to the vulnerable system itself (GitHub Advisory, NI Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC data indicates exploitation is assessed as "none" and the vulnerability is not automatable. The EPSS score is approximately 0.128% (3rd percentile), reflecting a low near-term exploitation probability. No threat actor attribution has been reported.
.vi files received via email attachments, file shares, or downloads from untrusted sources; newly created or modified files in LabVIEW project directories following file open events.cmd.exe, powershell.exe, sh, curl, or network utilities) that are not part of normal LabVIEW operation; LabVIEW process crashes or abnormal terminations after opening a VI file.NI has released patched versions addressing this vulnerability: LabVIEW 23.3.10 (for the 2023 Q3 branch), 24.3.7 (for the 2024 branch), 25.3.5 (for the 2025 branch), and 26.3.1 (for the 2026 branch). Users should update to the appropriate patched release as the primary remediation step. As interim workarounds, organizations should educate users to avoid opening VI files from untrusted or unknown sources, restrict file-opening permissions where feasible, and consider application whitelisting to limit unauthorized code execution (NI Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."