Memory Corruption Vulnerability in NI LabVIEW Software
CVE-2026-32861

8.5HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-32861?

A memory corruption issue has been identified in NI LabVIEW, caused by an out-of-bounds write when processing a malformed LVCLASS file. This flaw could potentially allow attackers to exploit the vulnerability by tricking a user into opening a specially crafted .lvclass file, leading to information disclosure or arbitrary code execution. It is essential for users to be aware of the versions impacted, including NI LabVIEW 2026 Q1 (26.1.0) and earlier releases, to mitigate possible security risks.

Affected Version(s)

LabVIEW 0 < 23.0.0

LabVIEW 23.1.0 < 23.3.9

LabVIEW 24.1.0 < 24.3.6

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rocco Calvi (@TecR0c) with TecSecurity
TrendAI Zero Day Initiative
.