CVE-2026-18444

Summary

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

Affected Software

VendorProductVersion RangeStatus
NILabVIEW0 < 23.0.0affected
NILabVIEW23.1.0 < 23.3.10affected
NILabVIEW24.1.0 < 24.3.7affected
NILabVIEW25.1.0 < 25.3.5affected
NILabVIEW26.1.0 < 26.3.1affected

Weaknesses

  • CWE-195: CWE-195 Signed to unsigned conversion error

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References