CVE-2026-32860 Details
Description
There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
A memory corruption vulnerability has been identified in NI LabVIEW versions 2026 Q1 (26.1.0) and prior. This vulnerability arises from an out-of-bounds write when the application loads a corrupted LVLIB file. Exploitation of this issue could lead to information disclosure or arbitrary code execution. To successfully exploit this vulnerability, an attacker must convince a user to open a specially crafted .lvlib file.
Users are advised to upgrade to LabVIEW 2026 Q1 Patch 1 or later. Instructions for downloading the patch are available on the NI website. For LabVIEW 2025, 2024, 2023, and 2022, specific upgrade guidance is also provided on the NI website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni labview | <= 2022 2023 q1 2023 q3 2023 q3_patch1 2023 q3_patch2 2023 q3_patch3 2023 q3_patch4 2023 q3_patch5 2023 q3_patch6 2023 q3_patch7 2023 q3_patch8 2024 - 2024 q1 2024 q1_patch1 2024 q3 2024 q3_patch1 2024 q3_patch2 2024 q3_patch3 2024 q3_patch4 2024 q3_patch5 2025 q1 2025 q1_patch1 2025 q1_patch2 2025 q1_patch3 2025 q3 2025 q3_patch1 2025 q3_patch2 2025 q3_patch3 2026 q1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | New CVE Received | [email protected] |