ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “ZDI publishes two NI LabVIEW VI file parsing information disclosure advisories: ZDI-26-631 (CVE-2026-18444) and ZDI-26-630 (CVE-2026-18445)” — merged summary and timeline →

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

lowAdvisoryimportance 15CVE-2026-18444
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-631 describing an out-of-bounds read vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18444
Out-of-Bounds Read in NI LabVIEW Image Loading Enables Code Execution via Crafted VI

NI LabVIEW contains an integer conversion flaw (CWE-195) that causes an out-of-bounds read while loading images embedded in VI files. An attacker must persuade a user to open a specially crafted VI file, so exploitation depends on social engineering rather than a network-reachable service. If successful, the attacker can read memory for information disclosure or potentially achieve arbitrary code execution in the context of the LabVIEW user. Anyone running NI LabVIEW 2026 Q3 or any earlier version is affected, which spans a large share of the product's long-lived installed base. The issue was disclosed through ZDI (ZDI-26-631), but no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%.

Do: Upgrade LabVIEW to a release newer than 2026 Q3 once NI's patched build (see ZDI-26-631 and NI's advisory) is available in your maintenance channel. Until then, instruct staff not to open VI files from untrusted or unexpected sources, and inventory engineering workstations and test systems running LabVIEW 2026 Q3 or older to plan the update.

6.9<1%
  • ni labview NI LabVIEW 2026 Q3 and all prior versions
largeon the order of 100,000+ installed seats (NI's long-established engineering/test user base)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.

This source does not provide full text. Read it at zerodayinitiative.com.