ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability
ZDI disclosed CVE-2026-18445, an integer overflow in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.
The Zero Day Initiative published advisory ZDI-26-630 describing an integer overflow vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18445 | Integer Overflow Out-of-Bounds Write in NI LabVIEW VI File Parsing NI LabVIEW contains an integer overflow (CWE-190) when parsing VI files, which can lead to an out-of-bounds write in memory. The flaw is triggered when an attacker convinces a user to open a specially crafted .VI file, so exploitation depends on local user interaction rather than exposure of a network service. A successful attack can disclose sensitive information or achieve arbitrary code execution on the victim's machine. All NI LabVIEW versions up to and including 2026 Q3 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days. Do: Monitor NI's security bulletin for CVE-2026-18445 and upgrade all LabVIEW installations (2026 Q3 and earlier) to the patched release once NI publishes it. Until then, instruct engineering and test teams not to open .VI files from untrusted or unexpected sources, and consider email/web filtering of .VI attachments as an interim mitigation. Given the low EPSS score and lack of public PoC, urgent action is not required, but inventorying LabVIEW versions in your environment is prudent. | 6.9 | <1% |
| large≈300,000+ LabVIEW users/installed seats (order of hundreds of thousands) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.
This source does not provide full text. Read it at zerodayinitiative.com.