CVE-2026-32860
7.8NI · LabVIEW
NI LabVIEW contains an out of bounds write vulnerability during the parsing of .lvlib files, which can lead to arbitrary code execution or information disclosure.
Executive summary
A memory corruption vulnerability in NI LabVIEW allows for arbitrary code execution if a user opens a specially crafted project library file.
Vulnerability
This is an out of bounds write flaw (CWE-787) triggered when the software parses a corrupted .lvlib file. Exploitation requires user interaction to open the malicious file, but once triggered, it can lead to code execution.
Business impact
The potential for arbitrary code execution poses a severe risk to the integrity and confidentiality of systems running LabVIEW. With a CVSS score of 7.8, this high severity flaw could allow an attacker to gain full control over the workstation or extract sensitive project data, potentially disrupting engineering workflows and exposing proprietary intellectual property.
Remediation
Immediate Action: Update NI LabVIEW to the latest patched version as specified in the official NI security advisory.
Proactive Monitoring: Monitor endpoint activity for unusual process spawning or unexpected file system modifications initiated by the LabVIEW application.
Compensating Controls: Advise users to exercise extreme caution and refrain from opening project library files (.lvlib) from untrusted or unknown sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution and the high CVSS score, organizations should prioritize patching all affected LabVIEW installations. IT administrators must ensure that users are aware of the risks associated with opening untrusted files, while simultaneously deploying the vendor provided security updates to eliminate the underlying memory corruption flaw.
More NI CVEs
Sources
Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity, with TrendAI Zero Day Initiative (coordinator), per the CVE Program record.