CVE-2026-18444
Received Received - Intake

Integer Conversion Out-of-Bounds Read in NI LabVIEW

Vulnerability report for CVE-2026-18444, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: National Instruments

Description

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ni labview to 2026_q3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-195 The product uses a signed primitive and performs a cast to an unsigned primitive, which can produce an unexpected value if the value of the signed primitive can not be represented using an unsigned primitive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18444 is an integer conversion vulnerability in NI LabVIEW that causes an out-of-bounds read when loading images. This flaw may allow attackers to disclose sensitive information or execute arbitrary code if a user opens a specially crafted VI file.

Detection Guidance

Detection primarily involves monitoring for suspicious VI files or unusual LabVIEW behavior. Check for recently opened or modified VI files from untrusted sources. NI does not provide specific detection commands, but inspecting file hashes and network traffic for LabVIEW-related processes may help.

Impact Analysis

If exploited, this vulnerability could lead to information disclosure or arbitrary code execution. Successful exploitation requires a user to open a malicious VI file, making it dependent on user interaction.

Compliance Impact

The vulnerability may lead to information disclosure or arbitrary code execution, which could result in unauthorized access to sensitive data. This could potentially violate compliance requirements under GDPR (e.g., unauthorized data access) or HIPAA (e.g., exposure of protected health information).

Mitigation Strategies

Immediately upgrade LabVIEW to the latest patched versions (2026 Q3 Patch 1 or later for 2026, 2025 Q3 Patch 5 or later for 2025) via NI Package Manager, Software Downloads, or NI Update Service. Avoid opening VI files from untrusted sources until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18444. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart