NI LabVIEW
cpe:2.3:a:ni:labview:*:*:*:*:*:*:*
- <= 26.1.0
A memory corruption vulnerability has been identified in NI LabVIEW versions through 2026 Q1 (26.1.0), caused by an out-of-bounds read in the function mgcore_SH_25_3!aligned_free(). This vulnerability could lead to information disclosure or arbitrary code execution. Exploitation requires a user to open a specially crafted VI file.
Exploitation of this vulnerability could result in memory corruption, allowing for information disclosure or arbitrary code execution.
Users are advised to upgrade to LabVIEW 2026 Q1 Patch 1 or later. Instructions for downloading the patch are available on the NI website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.