Executive brief
NI LabVIEW is a graphical programming environment used by engineers and scientists to design test, measurement, and control systems. CVE-2026-64204 is an out-of-bounds write vulnerability that allows attackers to execute arbitrary code or disclose sensitive information if a user opens a specially crafted VI (virtual instrument) file. Affected organizations could experience unauthorized code execution, data theft, or system compromise.
Technical details
CVE-2026-64204 is an out-of-bounds write vulnerability occurring when freeing TDRefCountedPtr objects in NI LabVIEW. The vulnerability is triggered by memory corruption in the memory management code, allowing an attacker to write data beyond the bounds of allocated memory. Exploitation requires user interaction: an attacker must convince a user to open a specially crafted VI file. Once triggered, the vulnerability enables arbitrary code execution with the privileges of the user running LabVIEW, as well as information disclosure. The vulnerability affects LabVIEW 2026 Q3 (26.3.0) and prior versions. NI has released patches available through NI Package Manager, Software Downloads, and NI Update Service.
Affected products
- NI LabVIEW 2026 Q3 (26.3.0) and prior
Timeline
- 2026-08-25: disclosed
- 2026-08-24: advisory