Junglewise Threat Intelligence

CVE-2026-16233: NI LabVIEW memory corruption in aligned_free function

CVE-2026-16233 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW is a software development environment used by engineers and scientists for automated testing and data acquisition. A memory corruption vulnerability in the aligned_free() function can be exploited when a user opens a specially crafted file, leading to arbitrary code execution or information disclosure. This could allow attackers to gain control of systems running vulnerable versions of LabVIEW.

Technical details

CVE-2026-16233 is an out-of-bounds write vulnerability in the aligned_free() function of NI LabVIEW. The vulnerability requires local access and user interaction (opening a specially crafted VI file). No authentication is required. Successful exploitation can result in information disclosure, arbitrary code execution, and denial of service. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and prior versions. Patches are available through NI Update Service and NI Package Manager.

Affected products

  • NI LabVIEW 2026 Q3 (26.3.0) and prior

Timeline

  • 2026-08-25: disclosed: Vulnerability publicly disclosed by NI
  • 2026-08-25: patched: Patches available for LabVIEW 2026 Q3 Patch 1, 2025 Q3 Patch 5, 2024 Q3 Patch 7, and 2023 Q3 Patch 10

References

Related threats