CVE-2026-32861: Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass file
There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32861?
CVE-2026-32861 is classified as a critical severity vulnerability due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2026-32861?
To remediate CVE-2026-32861, update NI LabVIEW to the latest version or apply the security patches provided by National Instruments.
Which versions of NI LabVIEW are affected by CVE-2026-32861?
CVE-2026-32861 affects NI LabVIEW versions up to and including 26.1.0 and specific versions from 2023 onward.
What could happen if I don't address CVE-2026-32861?
Failing to address CVE-2026-32861 could lead to unauthorized information disclosure or the execution of arbitrary code on affected systems.
Is this the first time CVE-2026-32861 has been reported?
CVE-2026-32861 is a newly reported vulnerability that highlights a memory corruption issue during the loading of corrupted LVCLASS files in NI LabVIEW.