CVE-2026-32861

7.8

NI · LabVIEW

A memory corruption vulnerability in NI LabVIEW allows for arbitrary code execution or information disclosure via a specially crafted .lvclass file.

Executive summary

A critical memory corruption vulnerability in NI LabVIEW could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious file.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) triggered when the application parses a corrupted .lvclass file. The attack requires user interaction, specifically convincing a user to open a malicious file, but does not require prior authentication.

Business impact

Successful exploitation poses a severe risk to organizational security, as it can lead to full system compromise or unauthorized information disclosure. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the potential for significant impact on system integrity and confidentiality if an attacker successfully executes code in the context of the user.

Remediation

Immediate Action: Update all instances of NI LabVIEW to the latest patched versions provided in the official NI security advisory.

Proactive Monitoring: Monitor host systems for abnormal process crashes or unexpected file access patterns associated with LabVIEW project files.

Compensating Controls: Implement strict email filtering and endpoint protection to prevent users from opening untrusted or unsolicited .lvclass files from external sources.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or proof-of-concept available at this time.

Analyst recommendation

Organizations utilizing NI LabVIEW must prioritize applying the vendor provided security updates to mitigate the risk of arbitrary code execution. Given the nature of the flaw, user awareness training regarding the risks of opening files from untrusted sources remains a critical secondary layer of defense.

More NI CVEs

Sources

Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity, with TrendAI Zero Day Initiative (coordinator), per the CVE Program record.