National Instruments
First CVE: Oct 5, 2023Active for: 3 years
83
CVEs Published
More CVEs Published than 68% of tracked CNAs
20.8
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by National Instruments as a CNA, 89.2% affect products that National Instruments develops as a vendor.
89.2%
10.8%
Self-reported: 74Third-party: 9
Of all the CVEs published that affect products developed by National Instruments, 82.2% are self-published by National Instruments as a CNA.
82.2%
17.8%
Self-published: 74Published by other CNAs: 16
Trends Over Time
The number and severity of CVEs published by National Instruments over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2023
2 years ago
Most Recent CVE
Jun 19, 2026
35 days ago
Top CVEs
All CVEs published by National Instruments as a CNA, regardless of affected vendor or product.
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48137CRITICAL There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentiall | Jun 19, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-9142CRITICAL There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthent | Jun 19, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-9051CRITICAL There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication con | May 29, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-8036HIGH Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects | Jun 2, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-48139HIGH There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Succ | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48138HIGH There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requi | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2024-6793CRITICAL A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker | Jul 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-6806CRITICAL The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affect | Jul 22, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-4044HIGH A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation r | May 14, 2024 | 7.8 | 29 | NO | NO |
CVE-2026-48141HIGH There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion. This affects NI grpc-device 2.17.0 and prior versions. | Jun 19, 2026 | 7.5 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA83 CVEs
83%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local68 (81.9%)
Network14 (16.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.2%)
Attack Complexity
Low83 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None28 (33.7%)
Unknown0 (0.0%)
Required55 (66.3%)
Privileges Required
Low14 (16.9%)
High0 (0.0%)
None69 (83.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (83 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by National Instruments as a CNA.
Media Mentions
Media articles that mention a CVE ID published by National Instruments as a CNA — matched by CVE ID, not by organization name.