CVE-2026-18444

EUVD-2026-65601
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NICNA
6.6 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nilabview
𝑥
< 23.0.0
CNA
nilabview
23.1.0 ≤
𝑥
< 23.3.10
CNA
nilabview
24.1.0 ≤
𝑥
< 24.3.7
CNA
nilabview
25.1.0 ≤
𝑥
< 25.3.5
CNA
nilabview
26.1.0 ≤
𝑥
< 26.3.1
CNA