ZDI publishes two NI LabVIEW VI file parsing information disclosure advisories: ZDI-26-631 (CVE-2026-18444) and ZDI-26-630 (CVE-2026-18445)
On 2026-09-09, the Zero Day Initiative published two advisories for NI LabVIEW VI file parsing vulnerabilities that can disclose sensitive information: an out-of-bounds read tracked as CVE-2026-18444 (ZDI-26-631) and an integer overflow tracked as…
The Zero Day Initiative published two advisories on 2026-09-09 describing vulnerabilities in NI LabVIEW's parsing of VI files. Advisory ZDI-26-631 describes an out-of-bounds read vulnerability assigned CVE-2026-18444. Advisory ZDI-26-630 describes an integer overflow vulnerability assigned CVE-2026-18445. In both cases, exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned both flaws a CVSS rating of 3.3. The reports do not state affected LabVIEW versions, patched versions, or fixes, and no source disagreements exist between the two advisories.
- Advisory ZDI-26-631 (published 2026-09-09T05:00:00Z) covers an out-of-bounds read in NI LabVIEW's parsing of VI files, tracked as CVE-2026-18444.
- Advisory ZDI-26-630 (published 2026-09-09T05:00:00Z) covers an integer overflow in NI LabVIEW's parsing of VI files, tracked as CVE-2026-18445.
- Both vulnerabilities can disclose sensitive information (information disclosure impact).
- Exploitation of both vulnerabilities requires user interaction, such as visiting a malicious page or opening a malicious file.
- ZDI assigned both flaws a CVSS rating of 3.3.
- The reports do not specify affected LabVIEW versions, patched versions, or vendor fixes.
Coverage timelineoldest first · each row is one article
- · 6d agoZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI disclosed CVE-2026-18445, an integer overflow in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.
- · 6d agoZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 15
ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18444 +1 in the same advisory: …18445 | Out-of-Bounds Read in NI LabVIEW Image Loading Enables Code Execution via Crafted VI NI LabVIEW contains an integer conversion flaw (CWE-195) that causes an out-of-bounds read while loading images embedded in VI files. An attacker must persuade a user to open a specially crafted VI file, so exploitation depends on social engineering rather than a network-reachable service. If successful, the attacker can read memory for information disclosure or potentially achieve arbitrary code execution in the context of the LabVIEW user. Anyone running NI LabVIEW 2026 Q3 or any earlier version is affected, which spans a large share of the product's long-lived installed base. The issue was disclosed through ZDI (ZDI-26-631), but no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%. Do: Upgrade LabVIEW to a release newer than 2026 Q3 once NI's patched build (see ZDI-26-631 and NI's advisory) is available in your maintenance channel. Until then, instruct staff not to open VI files from untrusted or unexpected sources, and inventory engineering workstations and test systems running LabVIEW 2026 Q3 or older to plan the update. | 6.9 | <1% |
| largeon the order of 100,000+ installed seats (NI's long-established engineering/test user base) |