CVE-2026-32860: Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvlib file
There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32860?
The severity of CVE-2026-32860 is considered critical due to its potential for arbitrary code execution.
How do I fix CVE-2026-32860?
To fix CVE-2026-32860, update NI LabVIEW to the latest version or apply the available patches provided by National Instruments.
What are the potential impacts of CVE-2026-32860?
CVE-2026-32860 may result in memory corruption, leading to information disclosure or arbitrary code execution.
Which versions of NI LabVIEW are affected by CVE-2026-32860?
CVE-2026-32860 affects NI LabVIEW versions up to and including 26.1.0, along with various other specific versions and patches.
How can I determine if my system is vulnerable to CVE-2026-32860?
Check if you are using an affected version of NI LabVIEW as listed in the CVE description.