CVE-2026-16234: Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users of NI LabVIEW 2026 Q3 (26.3.0) and prior versions are affected. Exploitation requires a user to open a specially crafted VI file.
Does an attacker need prior access or authentication to exploit it?
No prior privileges are required according to the supplied vector. However, the attacker must persuade or otherwise cause a user to open the crafted VI.
What could happen if exploitation succeeds?
Successful exploitation may result in information disclosure or arbitrary code execution. The reported impact includes compromise of confidentiality, integrity, and availability.