Multiple Vulnerabilities in NI LabVIEW Lead to Potential Code Execution Risks

Multiple Vulnerabilities in NI LabVIEW Lead to Potential Code Execution Risks

First seen 9 Sep 2026, 22:43 UTC Zerodayinitiativewww.ni.comwww.cve.org 45.9

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in NI LabVIEW, affecting versions 2026 Q3 and earlier. CVE-2026-18444 involves an integer conversion vulnerability that can lead to an out-of-bounds read, while CVE-2026-18445 pertains to an integer overflow vulnerability causing an out-of-bounds write. Both vulnerabilities require user interaction to exploit, specifically by opening a specially crafted VI file. Successful exploitation may allow attackers to disclose sensitive information or execute arbitrary code. NI has issued advisories recommending users to upgrade their software to mitigate these risks. The vulnerabilities were reported by Grigory Dorodnov of TrendAI Research and have been assigned CVSS scores of 6.6 and 6.9 respectively. The vulnerabilities have been publicly disclosed today, September 9, 2026.

Key Points: • Two vulnerabilities in NI LabVIEW identified: CVE-2026-18444 and CVE-2026-18445. • Both vulnerabilities require user interaction to exploit via specially crafted VI files. • NI recommends immediate software upgrades to mitigate potential risks.

Ask AI about this cluster

Timeline

2026-06-30
Vulnerabilities reported to vendor
Grigory Dorodnov of TrendAI Research reported the vulnerabilities to NI for remediation.
Zerodayinitiative
2026-08-25
CVE-2026-18444 and CVE-2026-18445 published
NI disclosed two vulnerabilities in LabVIEW, affecting versions 2026 Q3 and earlier.
NI
2026-09-09
Advisories publicly released
NI and Zerodayinitiative coordinated the public release of advisories detailing the vulnerabilities.
NI