Junglewise Threat Intelligence

CVE-2026-32862: NI LabVIEW out-of-bounds write in ResFileFactory::InitResourceMgr

CVE-2026-32862 · Severity: high · CVSS 7.8 · Published 2026-04-07

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW, a popular system-design platform and development environment for engineers, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted LabVIEW Virtual Instrument (.vi) file. If successful, this could allow the attacker to steal sensitive information or take full control of the affected computer.

Technical details

A memory corruption vulnerability exists in NI LabVIEW due to an out-of-bounds write (CWE-787) within the ResFileFactory::InitResourceMgr() function. The vulnerability is triggered when the application processes a specially crafted VI file. An attacker with no special privileges can exploit this locally by convincing a legitimate user to open the malicious file (user interaction required). Successful exploitation can lead to arbitrary code execution or unauthorized information disclosure. NI has released patches for various versions, including LabVIEW 2026 Q1 Patch 1, 2025 Q3 Patch 4, 2024 Q3 Patch 6, and 2023 Q3 Patch 9.

Affected products

  • NI LabVIEW 2026 Q1 (26.1.0) and prior versions

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched

References

Related threats