HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

Out‑of‑Bounds Read Information Disclosure in NI LabVIEW (CVE‑2026‑18444)

NI LabVIEW’s VI file parser can be tricked into reading beyond a buffer, leaking data when a user opens a malicious file or page. The flaw underscores the importance of continuous vulnerability management and auditable patch evidence for compliance readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Out‑of‑Bounds Read Information Disclosure in NI LabVIEW (CVE‑2026‑18444)

What It Is – NI LabVIEW contains an out‑of‑bounds read flaw in the parsing of VI files. An attacker who can convince a user to open a crafted file or visit a malicious page can cause the LabVIEW process to read memory beyond the allocated buffer, leaking low‑sensitivity data.

Exploitability – The vulnerability requires user interaction (malicious file or page) and has a CVSS 3.3 (moderate) score. No public exploit code is known, but the attack vector is practical for targeted phishing or supply‑chain scenarios.

Affected Products – NI LabVIEW (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for continuous discovery and timely patching of software components used in engineering and test environments.
  • Evidence of Due Diligence – Maintaining an auditable record of patch deployment satisfies multiple framework controls (e.g., NIST CSF “Detect” and ISO 27001 “A.12.6”) with a single control objective.
  • Defensible Audit Trail – Automated collection of remediation evidence (patch version, deployment timestamps) supports the trust signal enterprises must provide to regulators and customers.

Recommended Actions

  1. Deploy NI’s September 2026 LabVIEW security update immediately.
  2. Verify patch status across all LabVIEW installations via an asset‑inventory scan.
  3. Incorporate the CVE into your vulnerability‑management workflow and map the remediation to the “Vulnerability Management” control area.
  4. Document the remediation steps and retain evidence for audit purposes.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-631/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →