Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-64203
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2026-64203 is a memory corruption vulnerability in NI LabVIEW that may result in information disclosure or arbitrary code execution. Disclosed on August 25, 2026, it affects NI LabVIEW 2026 Q3 (26.3.0) and all prior versions, specifically versions below 23.0.0, 23.1.0–23.3.10, 24.1.0–24.3.7, 25.1.0–25.3.5, and 26.1.0–26.3.1. Successful exploitation requires a user to open a specially crafted Virtual Instrument (VI) file. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, NI Advisory).

Technical details

The vulnerability is rooted in improper memory handling within NI LabVIEW's VI file parsing logic, classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker crafts a malicious VI file that, when opened by a victim, triggers out-of-bounds memory read or write operations, potentially corrupting process memory. The attack vector is local (the file must be opened on the target system), requires no privileges, and has low attack complexity — the primary precondition is user interaction (passive; the user must open the file). No public proof-of-concept code has been identified at this time (GitHub Advisory, NI Advisory).

Impact

Successful exploitation can lead to arbitrary code execution or sensitive information disclosure, with high impact to confidentiality, integrity, and availability of the affected system. Code execution would occur with the privileges of the user running LabVIEW, which in industrial or engineering environments may include access to sensitive measurement data, test configurations, or control system interfaces. Lateral movement potential depends on the victim's network access and privilege level, but the scope is limited to the vulnerable system itself (GitHub Advisory, NI Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC data indicates exploitation is assessed as "none" and the vulnerability is not automatable. The EPSS score is approximately 0.128% (3rd percentile), reflecting a low near-term exploitation probability. No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious VI file: An attacker creates a specially crafted NI LabVIEW Virtual Instrument (.vi) file designed to trigger out-of-bounds read or write operations during parsing, exploiting the memory corruption flaw in affected LabVIEW versions.
  2. Deliver the file to the target: The attacker distributes the malicious VI file via phishing email, file-sharing platforms, compromised repositories, or social engineering — targeting engineers or researchers who regularly work with LabVIEW.
  3. Induce the victim to open the file: The attacker convinces the target user to open the crafted VI file in a vulnerable version of NI LabVIEW (any version up to and including 26.3.0).
  4. Trigger memory corruption: Upon opening, LabVIEW's file parser processes the malformed VI, causing an out-of-bounds read (CWE-125) or write (CWE-787) that corrupts process memory.
  5. Achieve code execution or information disclosure: Depending on the nature of the corruption, the attacker may achieve arbitrary code execution with the privileges of the LabVIEW process, or read sensitive data from process memory (GitHub Advisory, NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email attachments, file shares, or downloads from untrusted sources; newly created or modified files in LabVIEW project directories following file open events.
  • Process: Unusual child processes spawned by the LabVIEW executable (e.g., cmd.exe, powershell.exe, sh, curl, or network utilities) that are not part of normal LabVIEW operation; LabVIEW process crashes or abnormal terminations after opening a VI file.
  • Logs: Application crash logs or Windows Error Reporting entries referencing LabVIEW with access violation or memory corruption errors; security event logs showing unexpected process creation under the LabVIEW user context.
  • Network: Unexpected outbound network connections originating from the LabVIEW process to external IP addresses, particularly shortly after a VI file is opened.

Mitigation and workarounds

NI has released patched versions addressing this vulnerability: LabVIEW 23.3.10 (for the 2023 Q3 branch), 24.3.7 (for the 2024 branch), 25.3.5 (for the 2025 branch), and 26.3.1 (for the 2026 branch). Users should update to the appropriate patched release as the primary remediation step. As interim workarounds, organizations should educate users to avoid opening VI files from untrusted or unknown sources, restrict file-opening permissions where feasible, and consider application whitelisting to limit unauthorized code execution (NI Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64204HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64203HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64202HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-64201HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026
CVE-2026-18445MEDIUM6.9
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management