Multiple Vulnerabilities in NI LabVIEW Lead to Potential Code Execution Risks
Article Content
Two critical vulnerabilities have been identified in NI LabVIEW, affecting versions 2026 Q3 and earlier. CVE-2026-18444 involves an integer conversion vulnerability that can lead to an out-of-bounds read, while CVE-2026-18445 pertains to an integer overflow vulnerability causing an out-of-bounds write. Both vulnerabilities require user interaction to exploit, specifically by opening a specially crafted VI file. Successful exploitation may allow attackers to disclose sensitive information or execute arbitrary code. NI has issued advisories recommending users to upgrade their software to mitigate these risks. The vulnerabilities were reported by Grigory Dorodnov of TrendAI Research and have been assigned CVSS scores of 6.6 and 6.9 respectively. The vulnerabilities have been publicly disclosed today, September 9, 2026.
Key Points: • Two vulnerabilities in NI LabVIEW identified: CVE-2026-18444 and CVE-2026-18445. • Both vulnerabilities require user interaction to exploit via specially crafted VI files. • NI recommends immediate software upgrades to mitigate potential risks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.