Several high-severity vulnerabilities have been identified in NI LabVIEW, affecting version 2025 Q3 (25.3) and earlier. These vulnerabilities include out-of-bounds reads and writes, stack-based buffer overflows, and use-after-free conditions in various LabVIEW components such as LVResFile::FindRsrcListEntry(), mgocre_SH_25_3!RevBL(), LVResource::DetachResource(), and sentry!sentry_span_set_data(). Exploitation of these flaws requires a user to open a specially crafted VI file, potentially leading to information disclosure or arbitrary code execution. The vulnerabilities are not remotely exploitable but pose significant risk if a malicious file is opened on a vulnerable system.
CISA has issued an advisory confirming that these vulnerabilities (CVE-2025-64461 through CVE-2025-64469) impact critical infrastructure sectors, including manufacturing, defense, IT, and transportation. The advisory recommends users update to the latest version of LabVIEW to mitigate these risks. All vulnerabilities have been assigned a CVSS v3 base score of 7.8 or higher, underscoring their severity and the importance of prompt remediation. No evidence of exploitation in the wild has been reported as of the latest advisories.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CISA issued advisory ICSA-25-352-03 covering the multiple high-severity NI LabVIEW vulnerabilities, stating there were no known reports of public exploitation and highlighting impact to sectors such as manufacturing, defense, IT, and transportation. The advisory recommended patching supported versions, noted LabVIEW 2021 no longer receives fixes, and credited Michael Heinzl with reporting the issues to CISA.
National Instruments disclosed a set of high-severity vulnerabilities in LabVIEW affecting versions 2021 through 2025 Q3, including out-of-bounds read/write, use-after-free, and stack-based buffer overflow flaws triggered by opening specially crafted VI files. NI published security advisories and patches for supported versions, while noting exploitation requires local user interaction and can lead to information disclosure or arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.