National Instruments disclosed two high-severity memory corruption vulnerabilities in NI LabVIEW that can be exploited when a user opens specially crafted project files. CVE-2026-32860 is an out-of-bounds write flaw (CWE-787) triggered while LabVIEW loads a corrupted .lvlib file, while CVE-2026-32864 is an out-of-bounds read issue (CWE-125) in mgcore_SH_25_3!aligned_free() that can be triggered through a malicious VI file. Both flaws may result in information disclosure or arbitrary code execution.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
NI recorded CVE-2026-32864 on 2026-04-07 for an out-of-bounds read in mgcore_SH_25_3!aligned_free() triggered by opening a specially crafted VI file. The vulnerability affects LabVIEW 2026 Q1 (26.1.0) and prior versions and could lead to information disclosure or arbitrary code execution.
NI recorded CVE-2026-32860 on 2026-04-07 for an out-of-bounds write in LabVIEW when loading a corrupted .lvlib file. The issue affects LabVIEW 2026 Q1 (26.1.0) and earlier versions and may allow information disclosure or arbitrary code execution with user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.