Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32863

29
FAUCET Score

CVE-2026-32863 is a memory corruption vulnerability involving an out-of-bounds read in the sentry_transaction_context_set_operation() function within NI LabVIEW versions 26.1.0 and earlier. The flaw could enable information disclosure or arbitrary code execution if an attacker successfully tricks a user into opening a malicious VI file. The vulnerability presents a HIGH severity risk with a CVSS score of 7.8, featuring a local attack vector with low complexity and no privilege requirements. The attack depends on user interaction, but once successful, it could compromise confidentiality, integrity, and availability of the affected system. There is no current evidence of active exploitation, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on the Hot List. The extremely low EPSS score of 0.00016 further indicates minimal real-world exploitation activity, suggesting this remains a theoretical threat requiring user intervention for successful compromise.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2022CPE matchmatch criteria
cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
2023CPE matchmatch criteria
cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:*
2023CPE matchmatch criteria
cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:*
2023CPE matchmatch criteria
cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:*
2023CPE matchmatch criteria
cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 7th percentile among its peer group of 11,617 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

ni.com / en/support/security/available-critical-and-security-updates-for-ni-software/2026/memory-corruption-vulnerabilities-in-ni-labview.html
Vendor Advisory