HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Out‑of‑Bounds Read Information Disclosure in NI LabVIEW (CVE‑2026‑18444)

NI LabVIEW’s VI file parser can be tricked into reading beyond a buffer, leaking data when a user opens a malicious file or page. The flaw underscores the importance of continuous vulnerability management and auditable patch evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Out‑of‑Bounds Read Information Disclosure in NI LabVIEW (CVE‑2026‑18444)

What It Is – NI LabVIEW contains an out‑of‑bounds read flaw in the parsing of VI files. An attacker who can convince a user to open a crafted file or visit a malicious page can cause the LabVIEW process to read memory beyond the allocated buffer, leaking low‑sensitivity data.

Exploitability – The vulnerability requires user interaction (malicious file or page) and has a CVSS 3.3 (moderate) score. No public exploit code is known, but the attack vector is practical for targeted phishing or supply‑chain scenarios.

Affected Products – NI LabVIEW (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for continuous discovery and timely patching of software components used in engineering and test environments.
  • Evidence of Due Diligence – Maintaining an auditable record of patch deployment satisfies multiple framework controls (e.g., NIST CSF “Detect” and ISO 27001 “A.12.6”) with a single control objective.
  • Defensible Audit Trail – Automated collection of remediation evidence (patch version, deployment timestamps) supports the trust signal enterprises must provide to regulators and customers.

Recommended Actions

  • Deploy NI’s September 2026 LabVIEW security update immediately.
  • Verify patch status across all LabVIEW installations via an asset‑inventory scan.
  • Incorporate the CVE into your vulnerability‑management workflow and map the remediation to the “Vulnerability Management” control area.
  • Document the remediation steps and retain evidence for audit purposes.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-631/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →