CVE-2026-32864: Out-of-Bounds Read in mgcore_SH_25_3!aligned_free()
There is a memory corruption vulnerability due to an out-of-bounds read in mgcoreSH253!alignedfree() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32864?
CVE-2026-32864 has been classified as a critical vulnerability due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2026-32864?
To fix CVE-2026-32864, upgrade to the latest version of NI LabVIEW that includes the security patches addressing this vulnerability.
What versions of NI LabVIEW are affected by CVE-2026-32864?
CVE-2026-32864 affects NI LabVIEW versions up to and including 26.1.0, as well as several specific 2023 and 2024 versions.
What exploitation methods are possible for CVE-2026-32864?
Exploitation of CVE-2026-32864 could allow an attacker to execute arbitrary code on vulnerable installations of NI LabVIEW.
Is CVE-2026-32864 related to any recent vulnerabilities in NI LabVIEW?
Yes, CVE-2026-32864 is part of ongoing concerns regarding security vulnerabilities in various versions of NI LabVIEW.