Local Privilege Escalation Vulnerability in NI-PAL Drivers
Article Content
- •CVE-2026-18485 affects NI-PAL versions 26.3.1 and earlier.
- •The vulnerability allows local privilege escalation on Windows systems.
- •Users must update their NI-PAL components before November 10, 2026, to avoid disruptions.
A local privilege escalation vulnerability, identified as CVE-2026-18485, was discovered in the NI-PAL kernel driver, affecting versions 26.3.1 and earlier. This flaw allows authenticated users to escalate privileges and execute arbitrary code on Microsoft Windows systems. Customers using NI driver software from Q2 2026 or earlier are urged to update their NI-PAL components to avoid potential system disruptions. The vulnerable driver is on Microsoft's blocklist, which will prevent it from loading starting November 10, 2026, if not updated. NI recommends that users verify their installed NI-PAL version and follow the mitigation guidance provided. The vulnerability has a CVSS score of 8.5, indicating a high severity level. Currently, there is no evidence of in the wild.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (2)
Following this threat?
Track CVE-2026-18485 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of NI-PAL are affected?
What should I do to protect my systems?
When will the vulnerable drivers be blocked?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…