OVERVIEW CVE-2026-32862 is a memory corruption vulnerability resulting from an out-of-bounds write in the ResFileFactory::InitResourceMgr() function of NI LabVIEW. The flaw affects NI LabVIEW 2026 Q1 (26.1.0) and all prior versions, requiring user interaction to exploit. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector, low attack complexity, and no privileges required. Successful exploitation demands that a user open a malicious VI file, after which an attacker could achieve information disclosure or arbitrary code execution with high impact across confidentiality, integrity, and availability. EXPLOITATION STATUS This vulnerability is not currently on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on the Hot List, indicating no evidence of active exploitation in the wild. The EPSS score of 0.0002 reflects exceptionally low probability of exploitation in real-world conditions. No public exploit code is currently available, and community attention remains minimal despite the vulnerability's potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022CPE matchmatch criteria | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.