{"schema_version":1,"title":"NI vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in NI: 0 in the last 7 days and 10 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-78474, was published on 16 September 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/ni","json_url":"https://junglewise.ai/threats/vendors/ni.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/ni","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":14,"all_time":23,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":10,"last_365_days":23},"latest":[{"cve":"CVE-2026-78474","cvss":5.3,"epss":0.0039,"slug":"cve-2026-78474-ni-woocommerce-sales-report-auth-bypass-in-report-printing","title":"Ni WooCommerce Sales Report auth bypass in report-printing","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:32.923+00:00","url":"https://junglewise.ai/threats/cve-2026-78474-ni-woocommerce-sales-report-auth-bypass-in-report-printing"},{"cve":"CVE-2026-78472","cvss":8.6,"epss":0.0045,"slug":"cve-2026-78472-ni-woocommerce-sales-report-sql-injection-via-sort-parameter","title":"Ni WooCommerce Sales Report SQL injection via sort parameter","severity":"high","exploited":false,"published_at":"2026-09-16T06:16:32.827+00:00","url":"https://junglewise.ai/threats/cve-2026-78472-ni-woocommerce-sales-report-sql-injection-via-sort-parameter"},{"cve":"CVE-2026-4129","cvss":8.1,"epss":0.0035,"slug":"cve-2026-4129-ni-systemlink-improper-access-control-vulnerability","title":"NI SystemLink improper access control vulnerability","severity":"high","exploited":false,"published_at":"2026-09-10T16:17:14.08+00:00","url":"https://junglewise.ai/threats/cve-2026-4129-ni-systemlink-improper-access-control-vulnerability"},{"cve":"CVE-2026-64204","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64204-ni-labview-out-of-bounds-write-in-tdrefcountedptr","title":"NI LabVIEW out-of-bounds write in TDRefCountedPtr","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.727+00:00","url":"https://junglewise.ai/threats/cve-2026-64204-ni-labview-out-of-bounds-write-in-tdrefcountedptr"},{"cve":"CVE-2026-64203","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64203-ni-labview-out-of-bounds-read-in-qualifiedname-prepend-function","title":"NI LabVIEW out-of-bounds read in QualifiedName prepend function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.587+00:00","url":"https://junglewise.ai/threats/cve-2026-64203-ni-labview-out-of-bounds-read-in-qualifiedname-prepend-function"},{"cve":"CVE-2026-64201","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64201-ni-labview-out-of-bounds-read-in-enqrunq-function","title":"NI LabVIEW out-of-bounds read in EnQRunQ function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.3+00:00","url":"https://junglewise.ai/threats/cve-2026-64201-ni-labview-out-of-bounds-read-in-enqrunq-function"},{"cve":"CVE-2026-18445","cvss":6.6,"epss":0.0013,"slug":"cve-2026-18445-ni-labview-integer-overflow-resulting-in-out-of-bounds-write","title":"NI LabVIEW integer overflow resulting in out-of-bounds write","severity":"medium","exploited":false,"published_at":"2026-08-25T17:17:06.093+00:00","url":"https://junglewise.ai/threats/cve-2026-18445-ni-labview-integer-overflow-resulting-in-out-of-bounds-write"},{"cve":"CVE-2026-18444","cvss":6.6,"epss":0.0013,"slug":"cve-2026-18444-ni-labview-integer-conversion-out-of-bounds-read-in-image-loading","title":"NI LabVIEW integer conversion out-of-bounds read in image loading","severity":"medium","exploited":false,"published_at":"2026-08-25T17:17:05.803+00:00","url":"https://junglewise.ai/threats/cve-2026-18444-ni-labview-integer-conversion-out-of-bounds-read-in-image-loading"},{"cve":"CVE-2026-16234","cvss":7.8,"epss":0.0013,"slug":"cve-2026-16234-ni-labview-out-of-bounds-read-in-stringutils-converter-function","title":"NI LabVIEW out-of-bounds read in StringUtils Converter function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:05.623+00:00","url":"https://junglewise.ai/threats/cve-2026-16234-ni-labview-out-of-bounds-read-in-stringutils-converter-function"},{"cve":"CVE-2026-16233","cvss":7.8,"epss":0.0013,"slug":"cve-2026-16233-ni-labview-memory-corruption-in-aligned-free-function","title":"NI LabVIEW memory corruption in aligned_free function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:05.447+00:00","url":"https://junglewise.ai/threats/cve-2026-16233-ni-labview-memory-corruption-in-aligned-free-function"},{"cve":"CVE-2026-9143","cvss":3.7,"slug":"cve-2026-9143-ni-grpc-device-incorrect-numeric-conversion-in-codegen","title":"NI grpc-device incorrect numeric conversion in CodeGen","severity":"low","exploited":false,"published_at":"2026-06-19T14:16:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-9143-ni-grpc-device-incorrect-numeric-conversion-in-codegen"},{"cve":"CVE-2026-9142","cvss":9.1,"slug":"cve-2026-9142-ni-grpc-device-missing-authentication-when-tls-is-disabled","title":"NI grpc-device missing authentication when TLS is disabled","severity":"critical","exploited":false,"published_at":"2026-06-19T14:16:24.423+00:00","url":"https://junglewise.ai/threats/cve-2026-9142-ni-grpc-device-missing-authentication-when-tls-is-disabled"},{"cve":"CVE-2026-48141","cvss":5.3,"slug":"cve-2026-48141-ni-grpc-device-memory-leak-in-beginsidebandstream","title":"NI grpc-device memory leak in BeginSidebandStream","severity":"medium","exploited":false,"published_at":"2026-06-19T14:16:23.19+00:00","url":"https://junglewise.ai/threats/cve-2026-48141-ni-grpc-device-memory-leak-in-beginsidebandstream"},{"cve":"CVE-2026-48140","cvss":6.5,"slug":"cve-2026-48140-ni-grpc-device-unchecked-enum-cast-in-beginsidebandstream","title":"NI grpc-device unchecked enum cast in BeginSidebandStream","severity":"medium","exploited":false,"published_at":"2026-06-19T14:16:23.063+00:00","url":"https://junglewise.ai/threats/cve-2026-48140-ni-grpc-device-unchecked-enum-cast-in-beginsidebandstream"},{"cve":"CVE-2026-48139","cvss":7.5,"slug":"cve-2026-48139-ni-grpc-device-null-pointer-dereference-in-data-moniker-service","title":"NI grpc-device NULL pointer dereference in data moniker service","severity":"high","exploited":false,"published_at":"2026-06-19T14:16:22.937+00:00","url":"https://junglewise.ai/threats/cve-2026-48139-ni-grpc-device-null-pointer-dereference-in-data-moniker-service"},{"cve":"CVE-2026-48138","cvss":7.5,"slug":"cve-2026-48138-ni-grpc-device-out-of-bounds-read-in-streaming-api","title":"NI grpc-device out-of-bounds read in streaming API","severity":"high","exploited":false,"published_at":"2026-06-19T14:16:22.817+00:00","url":"https://junglewise.ai/threats/cve-2026-48138-ni-grpc-device-out-of-bounds-read-in-streaming-api"},{"cve":"CVE-2026-48137","cvss":9.1,"slug":"cve-2026-48137-ni-grpc-device-remote-code-execution-in-sideband-streaming-api","title":"NI grpc-device remote code execution in sideband streaming API","severity":"critical","exploited":false,"published_at":"2026-06-19T14:16:22.68+00:00","url":"https://junglewise.ai/threats/cve-2026-48137-ni-grpc-device-remote-code-execution-in-sideband-streaming-api"},{"cve":"CVE-2026-9051","cvss":9.1,"slug":"cve-2026-9051-ni-systemlink-enterprise-authentication-bypass-in-dashboard","title":"NI SystemLink Enterprise authentication bypass in Dashboard","severity":"critical","exploited":false,"published_at":"2026-05-29T19:16:28.8+00:00","url":"https://junglewise.ai/threats/cve-2026-9051-ni-systemlink-enterprise-authentication-bypass-in-dashboard"},{"cve":"CVE-2026-32864","cvss":7.8,"epss":0.0014,"slug":"cve-2026-32864-ni-labview-out-of-bounds-read-in-mgcore-sh-25-3-aligned-free","title":"NI LabVIEW out-of-bounds read in mgcore_SH_25_3!aligned_free()","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:26.46+00:00","url":"https://junglewise.ai/threats/cve-2026-32864-ni-labview-out-of-bounds-read-in-mgcore-sh-25-3-aligned-free"},{"cve":"CVE-2026-32863","cvss":7.8,"epss":0.0019,"slug":"cve-2026-32863-ni-labview-out-of-bounds-read-in-sentry-transaction-context-set","title":"NI LabVIEW out-of-bounds read in sentry_transaction_context_set_operation","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:26.22+00:00","url":"https://junglewise.ai/threats/cve-2026-32863-ni-labview-out-of-bounds-read-in-sentry-transaction-context-set"},{"cve":"CVE-2026-32862","cvss":7.8,"epss":0.0015,"slug":"cve-2026-32862-ni-labview-out-of-bounds-write-in-resfilefactory-initresourcemgr","title":"NI LabVIEW out-of-bounds write in ResFileFactory::InitResourceMgr","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:24.883+00:00","url":"https://junglewise.ai/threats/cve-2026-32862-ni-labview-out-of-bounds-write-in-resfilefactory-initresourcemgr"},{"cve":"CVE-2026-32861","cvss":7.8,"epss":0.0022,"slug":"cve-2026-32861-ni-labview-out-of-bounds-write-in-lvclass-file-parsing","title":"NI LabVIEW out-of-bounds write in LVCLASS file parsing","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:24.363+00:00","url":"https://junglewise.ai/threats/cve-2026-32861-ni-labview-out-of-bounds-write-in-lvclass-file-parsing"},{"cve":"CVE-2026-32860","cvss":7.8,"epss":0.0022,"slug":"cve-2026-32860-ni-labview-out-of-bounds-write-in-lvlib-file-parsing","title":"NI LabVIEW out-of-bounds write in LVLIB file parsing","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:24.04+00:00","url":"https://junglewise.ai/threats/cve-2026-32860-ni-labview-out-of-bounds-write-in-lvlib-file-parsing"}],"vendor":{"hub":true,"name":"NI","slug":"ni","homepage":"https://www.ni.com/","description":"An American multinational company that produces automated test equipment and virtual instrumentation software.","url":"https://junglewise.ai/threats/vendors/ni"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-9142","cvss":9.1,"slug":"cve-2026-9142-ni-grpc-device-missing-authentication-when-tls-is-disabled","title":"NI grpc-device missing authentication when TLS is disabled","severity":"critical","exploited":false,"published_at":"2026-06-19T14:16:24.423+00:00","url":"https://junglewise.ai/threats/cve-2026-9142-ni-grpc-device-missing-authentication-when-tls-is-disabled"},{"cve":"CVE-2026-48137","cvss":9.1,"slug":"cve-2026-48137-ni-grpc-device-remote-code-execution-in-sideband-streaming-api","title":"NI grpc-device remote code execution in sideband streaming API","severity":"critical","exploited":false,"published_at":"2026-06-19T14:16:22.68+00:00","url":"https://junglewise.ai/threats/cve-2026-48137-ni-grpc-device-remote-code-execution-in-sideband-streaming-api"},{"cve":"CVE-2026-9051","cvss":9.1,"slug":"cve-2026-9051-ni-systemlink-enterprise-authentication-bypass-in-dashboard","title":"NI SystemLink Enterprise authentication bypass in Dashboard","severity":"critical","exploited":false,"published_at":"2026-05-29T19:16:28.8+00:00","url":"https://junglewise.ai/threats/cve-2026-9051-ni-systemlink-enterprise-authentication-bypass-in-dashboard"},{"cve":"CVE-2026-78472","cvss":8.6,"epss":0.0045,"slug":"cve-2026-78472-ni-woocommerce-sales-report-sql-injection-via-sort-parameter","title":"Ni WooCommerce Sales Report SQL injection via sort parameter","severity":"high","exploited":false,"published_at":"2026-09-16T06:16:32.827+00:00","url":"https://junglewise.ai/threats/cve-2026-78472-ni-woocommerce-sales-report-sql-injection-via-sort-parameter"},{"cve":"CVE-2026-4129","cvss":8.1,"epss":0.0035,"slug":"cve-2026-4129-ni-systemlink-improper-access-control-vulnerability","title":"NI SystemLink improper access control vulnerability","severity":"high","exploited":false,"published_at":"2026-09-10T16:17:14.08+00:00","url":"https://junglewise.ai/threats/cve-2026-4129-ni-systemlink-improper-access-control-vulnerability"},{"cve":"CVE-2026-32861","cvss":7.8,"epss":0.0022,"slug":"cve-2026-32861-ni-labview-out-of-bounds-write-in-lvclass-file-parsing","title":"NI LabVIEW out-of-bounds write in LVCLASS file parsing","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:24.363+00:00","url":"https://junglewise.ai/threats/cve-2026-32861-ni-labview-out-of-bounds-write-in-lvclass-file-parsing"},{"cve":"CVE-2026-32860","cvss":7.8,"epss":0.0022,"slug":"cve-2026-32860-ni-labview-out-of-bounds-write-in-lvlib-file-parsing","title":"NI LabVIEW out-of-bounds write in LVLIB file parsing","severity":"high","exploited":false,"published_at":"2026-04-07T20:16:24.04+00:00","url":"https://junglewise.ai/threats/cve-2026-32860-ni-labview-out-of-bounds-write-in-lvlib-file-parsing"},{"cve":"CVE-2026-64204","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64204-ni-labview-out-of-bounds-write-in-tdrefcountedptr","title":"NI LabVIEW out-of-bounds write in TDRefCountedPtr","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.727+00:00","url":"https://junglewise.ai/threats/cve-2026-64204-ni-labview-out-of-bounds-write-in-tdrefcountedptr"},{"cve":"CVE-2026-64203","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64203-ni-labview-out-of-bounds-read-in-qualifiedname-prepend-function","title":"NI LabVIEW out-of-bounds read in QualifiedName prepend function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.587+00:00","url":"https://junglewise.ai/threats/cve-2026-64203-ni-labview-out-of-bounds-read-in-qualifiedname-prepend-function"},{"cve":"CVE-2026-64201","cvss":7.8,"epss":0.0019,"slug":"cve-2026-64201-ni-labview-out-of-bounds-read-in-enqrunq-function","title":"NI LabVIEW out-of-bounds read in EnQRunQ function","severity":"high","exploited":false,"published_at":"2026-08-25T17:17:59.3+00:00","url":"https://junglewise.ai/threats/cve-2026-64201-ni-labview-out-of-bounds-read-in-enqrunq-function"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"NI LabVIEW","slug":"labview","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/labview"},{"name":"NI Grpc-Device","slug":"grpc-device","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/grpc-device"},{"name":"NI InstrumentStudio","slug":"instrumentstudio","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/instrumentstudio"},{"name":"NI Dasylab","slug":"dasylab","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/dasylab"}]}