Vulnerability Details CVE-2026-32864
There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.7%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-32864
-
-
cpe:2.3:a:ni:labview:16.0.0.49152
-
cpe:2.3:a:ni:labview:2012
-
cpe:2.3:a:ni:labview:2014
-
cpe:2.3:a:ni:labview:2015
-
cpe:2.3:a:ni:labview:2016
-
cpe:2.3:a:ni:labview:2017
-
cpe:2.3:a:ni:labview:2018
-
cpe:2.3:a:ni:labview:2019
-
cpe:2.3:a:ni:labview:2020
-
cpe:2.3:a:ni:labview:2021
-
cpe:2.3:a:ni:labview:2022
-
cpe:2.3:a:ni:labview:2023
-
cpe:2.3:a:ni:labview:2024
-
cpe:2.3:a:ni:labview:2025
-
cpe:2.3:a:ni:labview:2026