ZeroHour

CVE-2026-18444

large

Out-of-Bounds Read in NI LabVIEW Image Loading Enables Code Execution via Crafted VI

CVSS 4.0
6.9 medium
EPSS
<1%p3
Published
()
Modified
AI analysis

NI LabVIEW contains an integer conversion flaw (CWE-195) that causes an out-of-bounds read while loading images embedded in VI files. An attacker must persuade a user to open a specially crafted VI file, so exploitation depends on social engineering rather than a network-reachable service. If successful, the attacker can read memory for information disclosure or potentially achieve arbitrary code execution in the context of the LabVIEW user. Anyone running NI LabVIEW 2026 Q3 or any earlier version is affected, which spans a large share of the product's long-lived installed base. The issue was disclosed through ZDI (ZDI-26-631), but no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%.

What to do: Upgrade LabVIEW to a release newer than 2026 Q3 once NI's patched build (see ZDI-26-631 and NI's advisory) is available in your maintenance channel. Until then, instruct staff not to open VI files from untrusted or unexpected sources, and inventory engineering workstations and test systems running LabVIEW 2026 Q3 or older to plan the update.

Affected
ni labviewNI LabVIEW 2026 Q3 and all prior versions
Estimated exposure
largeon the order of 100,000+ installed seats (NI's long-established engineering/test user base) — LabVIEW is widely deployed on engineering and test-bench workstations across manufacturing, R&D and academic labs (commonly cited in the hundreds of thousands of users), and the '2026 Q3 and prior' range covers essentially the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

Vendors
ni
Products
labview
Weakness
CWE-195
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-631 describing an out-of-bounds read vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.