ZeroHour
Vendor

NI

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-631 describing an out-of-bounds read vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18445, an integer overflow in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-630 describing an integer overflow vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

Related CVEs

  • Out-of-Bounds Read in NI LabVIEW Image Loading Enables Code Execution via Crafted VI
    NI LabVIEW contains an integer conversion flaw (CWE-195) that causes an out-of-bounds read while loading images embedded in VI files. An attacker must persuade a user to open a specially crafted VI file, so exploitation depends on social engineering rather than a network-reachable service. If successful, the attacker can read memory for information disclosure or potentially achieve arbitrary code execution in the context of the LabVIEW user. Anyone running NI LabVIEW 2026 Q3 or any earlier version is affected, which spans a large share of the product's long-lived installed base. The issue was disclosed through ZDI (ZDI-26-631), but no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%.
    · ni labview NI LabVIEW 2026 Q3 and all prior versionslarge
  • Integer Overflow Out-of-Bounds Write in NI LabVIEW VI File Parsing
    NI LabVIEW contains an integer overflow (CWE-190) when parsing VI files, which can lead to an out-of-bounds write in memory. The flaw is triggered when an attacker convinces a user to open a specially crafted .VI file, so exploitation depends on local user interaction rather than exposure of a network service. A successful attack can disclose sensitive information or achieve arbitrary code execution on the victim's machine. All NI LabVIEW versions up to and including 2026 Q3 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.
    · NI (National Instruments) LabVIEW 2026 Q3 and all prior versionslarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.