Junglewise Threat Intelligence

CVE-2026-64202: National Instruments LabVIEW out-of-bounds read in LVGetFileType

CVE-2026-64202 · Severity: high · CVSS 7.8 · Published 2026-08-25

Executive brief

NI LabVIEW is a graphical programming platform used by engineers and scientists to develop test, measurement, and automation software. CVE-2026-64202 is an out-of-bounds memory read vulnerability in the LVGetFileType function that can result in information disclosure or arbitrary code execution when a user opens a specially crafted VI file. Exploitation requires user interaction but no authentication, and affects LabVIEW 2026 Q3 and earlier versions.

Technical details

CVE-2026-64202 is an out-of-bounds read vulnerability in the LVGetFileType function within NI LabVIEW. The attack vector is local and requires user interaction—specifically, the attacker must convince a user to open a malicious VI (Virtual Instrument) file. The vulnerability allows an attacker to read memory beyond intended bounds, potentially disclosing sensitive information or achieving arbitrary code execution. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and all prior versions. Patches are available through NI Package Manager, Software Downloads, or NI Update Service, with version-specific mitigations provided (e.g., LabVIEW 2026 Q3 Patch 1 or later).

Affected products

  • National Instruments LabVIEW 2026 Q3 (26.3.0) and prior

Timeline

  • 2026-08-25: disclosed
  • 2026-08-24: advisory: NI security advisory published

References