CVE-2026-32862: Out-of-Bounds Write in ResFileFactory::InitResourceMgr()
There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32862?
CVE-2026-32862 is classified as a critical vulnerability due to potential arbitrary code execution and information disclosure.
How do I fix CVE-2026-32862?
To fix CVE-2026-32862, it is recommended to update NI LabVIEW to the latest patch that addresses this vulnerability.
What versions of NI LabVIEW are affected by CVE-2026-32862?
CVE-2026-32862 affects NI LabVIEW versions up to 26.1.0 and various 2023, 2024, and 2025 patches.
What are the potential impacts of exploiting CVE-2026-32862?
Exploiting CVE-2026-32862 can lead to memory corruption, which may allow an attacker to execute arbitrary code or access sensitive information.
What mitigations exist for CVE-2026-32862?
The best mitigation for CVE-2026-32862 is to apply the latest security patches provided by NI for affected versions of LabVIEW.