Junglewise Threat Intelligence

CVE-2026-16234: NI LabVIEW out-of-bounds read in StringUtils Converter function

CVE-2026-16234 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW is a graphical programming platform used by engineers and scientists to develop measurement and automation applications. This vulnerability allows arbitrary code execution or information disclosure when a user opens a specially crafted LabVIEW VI file, potentially compromising system integrity and confidentiality.

Technical details

This is an out-of-bounds read vulnerability (CVE-2026-16234) in the StringUtils Converter function within NI LabVIEW. The vulnerability requires user interaction—an attacker must socially engineer a victim to open a malicious VI file. Successful exploitation can lead to information disclosure or arbitrary code execution with the privileges of the user running LabVIEW. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and earlier versions. NI has released patches available through NI Package Manager, Software Downloads, or NI Update Service for affected versions (2026, 2025, 2024, 2023, and 2022).

Affected products

  • NI LabVIEW 2026 Q3 (26.3.0) and prior

Timeline

  • 2026-08-25: disclosed
  • 2026-08-24: advisory

References

Related threats