To help protect your systems, customers using NI driver software 2026 Q2 or earlier should visit ni.com/ni-pal-update and follow the recommended actions.
To protect customer systems, we recommend all customers using versions of NI-PAL older than Q3 2026 to install a security update. NI-PAL, a component used in many NI drivers, is on the Microsoft vulnerable driver blocklist due to security issues described in CVE-2026-18485 . Beginning as early as November 10, 2026, Windows may block affected NI-PAL components from loading when the blocklist is enabled. If the update is not installed, NI software and hardware workflows may stop working after a Windows security update.
This targeted update affects only one component. It does not require a driver version upgrade and is backwards compatible with NI-PAL versions to at least NI-PAL 17.0.
Customer Impact of NI-PAL Being Blocked
Who Should Take Action
Required Actions—Verify NI-PAL Version and Update
Customer Impact of NI-PAL Being Blocked
As early as November 10, 2026, systems that have not been updated will encounter various errors in NI Measurement & Automation Explorer (MAX), NI Hardware Manager, or device drivers.
Who Should Take Action
Customers using NI software or hardware on Microsoft Windows systems should check the installed NI-PAL version. Systems with NI-PAL 26.3.1 or earlier are affected and should be updated. The vulnerable driver blocklist is enabled by default on Windows 11 and is not enabled by default on Windows 10, although settings may have been changed by the customer or IT organization.
Special Instructions for NI Semiconductor Test System (STS) Customers
NI STS Customers should follow the steps in the NI-PAL 2026 Q3 Security Update: Options for STS Customers document.
Special Instructions for NI SystemLink™ Software Customers
Refer to Updating Affected Systems to NI-PAL 2026 Q3 Using NI SystemLink for instructions to use NI SystemLink to update multiple affected systems.
Required Actions—Verify NI-PAL Version and Update
Check the installed version— Open %WinDir%\system32\drivers, locate nipalk.sys, open Properties, and review Product Version on the Details tab.
Install the update— If the version is 26.3.1 or earlier, install NI-PAL 2026 Q3 or later using NI Update Service or the offline installer from the NI-PAL download page . Note : If you are using NI Update Service, you may need to first update NI Package Manager to see the available update.
Restart the system— The update takes one minute to install and requires a restart.
Validate operation— After restarting, complete the recommended validation checks below. Confirm the device is available in NI MAX or NI Hardware Manager. Run Device Self-Test and Reset. Run a Test Panel or an example program that uses the hardware.
Confirm the device is available in NI MAX or NI Hardware Manager.
Run Device Self-Test and Reset.
Run a Test Panel or an example program that uses the hardware.
The following video shows the full upgrade process.
We do not recommend disabling the Microsoft vulnerable driver blocklist as a general workaround. Doing so can reduce Windows protection against known vulnerable kernel drivers.
No known exploits for CVE-2026-18485 were known at the time of the source announcement.
The Windows blocklist is enforced only on Windows systems. We encourage Linux customers to also follow the latest security advisories to ensure timely notice of critical and security-relevant NI software updates, and update software as needed to stay secure.
Read the CVE-2026-18485 security advisory
Get information NI security advisories and subscription
Enable periodic checking in NI Update Service
If you have any questions, concerns, or would like to this issue further, please don’t hesitate to reach out to our technical support team .
Windows is a trademark of the Microsoft group of companies. The registered trademark Linux® is used pursuant to a sublicense from LMI, the exclusive licensee of Linus Torvalds, owner of the mark on a worldwide basis.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
