AI analysis
NI LabVIEW contains an integer overflow (CWE-190) when parsing VI files, which can lead to an out-of-bounds write in memory. The flaw is triggered when an attacker convinces a user to open a specially crafted .VI file, so exploitation depends on local user interaction rather than exposure of a network service. A successful attack can disclose sensitive information or achieve arbitrary code execution on the victim's machine. All NI LabVIEW versions up to and including 2026 Q3 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.
What to do: Monitor NI's security bulletin for CVE-2026-18445 and upgrade all LabVIEW installations (2026 Q3 and earlier) to the patched release once NI publishes it. Until then, instruct engineering and test teams not to open .VI files from untrusted or unexpected sources, and consider email/web filtering of .VI attachments as an interim mitigation. Given the low EPSS score and lack of public PoC, urgent action is not required, but inventorying LabVIEW versions in your environment is prudent.
Affected
| NI (National Instruments) LabVIEW | 2026 Q3 and all prior versions |
Estimated exposure
large≈300,000+ LabVIEW users/installed seats (order of hundreds of thousands) — NI has publicly cited hundreds of thousands of engineers and scientists using LabVIEW, and because the attack only requires a user to open an untrusted .VI file, the plausible affected population is on the order of hundreds of thousands of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.