ZeroHour

CVE-2026-18445

large

Integer Overflow Out-of-Bounds Write in NI LabVIEW VI File Parsing

CVSS 4.0
6.9 medium
EPSS
<1%p3
Published
()
Modified
AI analysis

NI LabVIEW contains an integer overflow (CWE-190) when parsing VI files, which can lead to an out-of-bounds write in memory. The flaw is triggered when an attacker convinces a user to open a specially crafted .VI file, so exploitation depends on local user interaction rather than exposure of a network service. A successful attack can disclose sensitive information or achieve arbitrary code execution on the victim's machine. All NI LabVIEW versions up to and including 2026 Q3 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.

What to do: Monitor NI's security bulletin for CVE-2026-18445 and upgrade all LabVIEW installations (2026 Q3 and earlier) to the patched release once NI publishes it. Until then, instruct engineering and test teams not to open .VI files from untrusted or unexpected sources, and consider email/web filtering of .VI attachments as an interim mitigation. Given the low EPSS score and lack of public PoC, urgent action is not required, but inventorying LabVIEW versions in your environment is prudent.

Affected
NI (National Instruments) LabVIEW2026 Q3 and all prior versions
Estimated exposure
large≈300,000+ LabVIEW users/installed seats (order of hundreds of thousands) — NI has publicly cited hundreds of thousands of engineers and scientists using LabVIEW, and because the attack only requires a user to open an untrusted .VI file, the plausible affected population is on the order of hundreds of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

Vendors
ni
Products
labview
Weakness
CWE-190
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18445, an integer overflow in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-630 describing an integer overflow vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.