CVE-2026-64202: Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users of NI LabVIEW 2026 Q3 (26.3.0) and prior versions are affected if they open a specially crafted VI. Exploitation is local and requires user interaction.
What does an attacker need to do to exploit it?
An attacker must persuade or otherwise cause a user to open a maliciously crafted VI file in NI LabVIEW. No privileges are required before exploitation, but opening the file is required.
What could successful exploitation allow?
Successful exploitation may result in information disclosure or arbitrary code execution. The vulnerability is a memory corruption issue involving an out-of-bounds read when loading a VI.