CVE-2026-64204: Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
Published Aug 25, 2026
·Updated
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Affected Software
1 affected component
NI LabVIEW<=26.3.0
Event History
Aug 25, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Users running NI LabVIEW 2026 Q3 (26.3.0) or an earlier version are affected when they open a specially crafted VI.
2
What does an attacker need to exploit it?
The attacker must persuade a user to open a malicious VI. The vulnerability is locally exploitable and requires user interaction; no privileges are required.
3
What could happen if exploitation succeeds?
Successful exploitation may allow information disclosure or arbitrary code execution, with high impact to confidentiality, integrity, and availability.