Junglewise Threat Intelligence

CVE-2026-32860: NI LabVIEW out-of-bounds write in LVLIB file parsing

CVE-2026-32860 · Severity: high · CVSS 7.8 · Published 2026-04-07

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW, a system-design platform and development environment for engineers, is vulnerable to a memory corruption issue when processing project library files. An attacker could exploit this by tricking a user into opening a specially crafted .lvlib file, potentially leading to unauthorized data access or the execution of malicious code on the user's system. This could compromise the integrity of engineering workstations and any sensitive project data stored on them.

Technical details

A memory corruption vulnerability exists in NI LabVIEW due to an out-of-bounds write (CWE-787) during the parsing of LabVIEW Project Library (.lvlib) files. The flaw is triggered when the application attempts to load a corrupted or maliciously crafted file. An attacker can achieve arbitrary code execution or information disclosure in the context of the current user. Exploitation requires local access to the system and user interaction to open the malicious file. The vulnerability affects NI LabVIEW 2026 Q1 and all prior versions; NI recommends upgrading to LabVIEW 2026 Q1 Patch 1 or other relevant patches for older supported versions.

Affected products

  • NI LabVIEW 2026 Q1 (26.1.0) and prior versions

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory: Vendor advisory published by NI

References

Related threats