CVE-2026-64201: Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of NI LabVIEW 2026 Q3 (26.3.0) and prior versions are affected when they open VI files from untrusted or attacker-controlled sources.
What does an attacker need to do to exploit it?
The attacker must persuade a user to open a specially crafted VI. The vulnerability is locally exploitable and requires user interaction; no privileges are required before exploitation.
What could successful exploitation allow?
Successful exploitation may result in information disclosure or arbitrary code execution. The reported impact includes high confidentiality, integrity, and availability effects.