Memory Corruption Vulnerability in NI LabVIEW Software by National Instruments
CVE-2026-64204

8.5HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-64204?

A memory corruption issue has been identified in NI LabVIEW, which could potentially allow an attacker to execute arbitrary code or disclose sensitive information. This vulnerability occurs when a specially crafted Virtual Instrument (VI) is opened by the user. Effective mitigation involves ensuring that users are aware of the risks and do not open untrusted VIs. The affected versions include NI LabVIEW 2026 Q3 (26.3.0) and earlier, emphasizing the importance of applying security updates from National Instruments.

Affected Version(s)

LabVIEW 0 < 23.0.0

LabVIEW 23.1.0 < 23.3.10

LabVIEW 24.1.0 < 24.3.7

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.