NI LabVIEW Memory Corruption Vulnerability in LVLIB File Parsing Allowing Code Execution

Vulnerability

A memory corruption vulnerability has been identified in NI LabVIEW versions 2026 Q1 (26.1.0) and prior. This vulnerability arises from an out-of-bounds write when the application loads a corrupted LVLIB file. Exploitation of this issue could lead to information disclosure or arbitrary code execution. To successfully exploit this vulnerability, an attacker must convince a user to open a specially crafted .lvlib file.

Impact

Exploitation of this vulnerability could result in memory corruption, allowing for information disclosure or arbitrary code execution.

Remediation

Users are advised to upgrade to LabVIEW 2026 Q1 Patch 1 or later. Instructions for downloading the patch are available on the NI website. For LabVIEW 2025, 2024, 2023, and 2022, specific upgrade guidance is also provided on the NI website.

Added: Apr 7, 2026, 9:53 PM
Updated: Apr 7, 2026, 9:53 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.6
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.