Junglewise Threat Intelligence

CVE-2026-64201: NI LabVIEW out-of-bounds read in EnQRunQ function

CVE-2026-64201 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: NI Labview. Vendors: NI.

Executive brief

NI LabVIEW is a visual programming platform used by engineers and scientists to develop measurement and automation systems. CVE-2026-64201 is an out-of-bounds read vulnerability in the EnQRunQ function that can lead to information disclosure or arbitrary code execution when a user opens a specially crafted VI (LabVIEW file). Successful exploitation requires user interaction and could enable attackers to access sensitive data or take control of the affected system.

Technical details

CVE-2026-64201 is an out-of-bounds read vulnerability in the EnQRunQ function within NI LabVIEW. The vulnerability is triggered when a user opens a specially crafted VI file, making the attack vector local with required user interaction. An attacker can exploit this flaw to read arbitrary memory contents, potentially disclosing sensitive information, or in combination with other techniques, to achieve arbitrary code execution with the privileges of the LabVIEW process. Patches are available for LabVIEW 2023 through 2026 via NI Update Service or direct downloads; versions 2022 and prior are out of mainstream support.

Affected products

  • NI LabVIEW 2026 Q3 (26.3.0) and prior

Timeline

  • 2026-08-25: disclosed
  • 2026-08-24: advisory: NI security advisory published

References

Related threats