SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18444

MEDIUM · CVSS 6.6 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An integer conversion vulnerability in NI LabVIEW allows for an out-of-bounds read when processing specially crafted VI files, potentially leading to information disclosure or arbitrary code execution. Users of NI LabVIEW 2026 Q3 and earlier versions should prioritize addressing this issue, as successful exploitation requires user interaction to open the malicious file. Organizations utilizing these versions should implement mitigations to safeguard against potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18444
Severity
MEDIUM
CVSS
6.6
EPSS
0.13%

Original NVD Description

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)