Junglewise Threat Intelligence

CVE-2026-18444: NI LabVIEW integer conversion out-of-bounds read in image loading

CVE-2026-18444 · Severity: medium · CVSS 6.6 · Published 2026-08-25

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW is a visual programming platform used by engineers and scientists to develop automated measurement and control systems. A vulnerability in its image loading functionality allows attackers to craft malicious VI files that, when opened by a user, can disclose sensitive information from memory or execute arbitrary code on the affected system.

Technical details

The vulnerability is an integer conversion error (CWE-195: Signed to Unsigned Conversion Error) that results in an out-of-bounds read when LabVIEW processes specially crafted image data within VI files. The flaw exists in the image loading component and requires user interaction—a user must open a malicious VI file for exploitation to occur. Successful exploitation can lead to information disclosure through memory reads or arbitrary code execution. The vulnerability affects LabVIEW 2026 Q3 and earlier versions across multiple release branches (2026, 2025, 2024, 2023, and 2022). Patches are available through NI Package Manager, Software Downloads, or NI Update Service.

Affected products

  • NI LabVIEW 2026 Q3 and prior (including 2025, 2024, 2023, 2022 and earlier)

Timeline

  • 2026-08-25: disclosed
  • 2026-09-01: advisory: NI security advisory published with mitigation guidance
  • 2026-09-01: patched: Patches available: LabVIEW 2026 Q3 Patch 1, 2025 Q3 Patch 5, 2024 Q3 Patch 7, 2023 Q3 Patch 10

References

Related threats