Executive brief
NI LabVIEW is a graphical programming platform used by engineers and scientists to develop measurement and automation applications. This vulnerability allows arbitrary code execution or information disclosure when a user opens a specially crafted LabVIEW VI file, potentially compromising system integrity and confidentiality.
Technical details
This is an out-of-bounds read vulnerability (CVE-2026-16234) in the StringUtils Converter function within NI LabVIEW. The vulnerability requires user interaction—an attacker must socially engineer a victim to open a malicious VI file. Successful exploitation can lead to information disclosure or arbitrary code execution with the privileges of the user running LabVIEW. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and earlier versions. NI has released patches available through NI Package Manager, Software Downloads, or NI Update Service for affected versions (2026, 2025, 2024, 2023, and 2022).
Affected products
- NI LabVIEW 2026 Q3 (26.3.0) and prior
Timeline
- 2026-08-25: disclosed
- 2026-08-24: advisory