CVE-2026-16233: Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of NI LabVIEW 2026 Q3 (26.3.0) and prior versions are affected when they open a specially crafted VI. Exploitation is local and requires user interaction.
What must an attacker do to exploit the vulnerability?
The attacker must persuade a user to open a maliciously crafted VI file. No privileges are required before exploitation, but the user must interact with the file.
What could successful exploitation allow?
Successful exploitation may cause information disclosure or arbitrary code execution. The reported impact includes high confidentiality, integrity, and availability effects.