ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “ZDI publishes two NI LabVIEW VI file parsing information disclosure advisories: ZDI-26-631 (CVE-2026-18444) and ZDI-26-630 (CVE-2026-18445)” — merged summary and timeline →

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

lowAdvisoryimportance 15CVE-2026-18445
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-18445, an integer overflow in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-630 describing an integer overflow vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18445
Integer Overflow Out-of-Bounds Write in NI LabVIEW VI File Parsing

NI LabVIEW contains an integer overflow (CWE-190) when parsing VI files, which can lead to an out-of-bounds write in memory. The flaw is triggered when an attacker convinces a user to open a specially crafted .VI file, so exploitation depends on local user interaction rather than exposure of a network service. A successful attack can disclose sensitive information or achieve arbitrary code execution on the victim's machine. All NI LabVIEW versions up to and including 2026 Q3 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.

Do: Monitor NI's security bulletin for CVE-2026-18445 and upgrade all LabVIEW installations (2026 Q3 and earlier) to the patched release once NI publishes it. Until then, instruct engineering and test teams not to open .VI files from untrusted or unexpected sources, and consider email/web filtering of .VI attachments as an interim mitigation. Given the low EPSS score and lack of public PoC, urgent action is not required, but inventorying LabVIEW versions in your environment is prudent.

6.9<1%
  • NI (National Instruments) LabVIEW 2026 Q3 and all prior versions
large≈300,000+ LabVIEW users/installed seats (order of hundreds of thousands)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.

This source does not provide full text. Read it at zerodayinitiative.com.