OVERVIEW CVE-2026-32864 is a memory corruption vulnerability affecting NI LabVIEW 2026 Q1 (26.1.0) and prior versions. The flaw exists as an out-of-bounds read in the mgcore_SH_25_3!aligned_free() function and can be exploited when a user opens a specially crafted VI file, potentially leading to information disclosure or arbitrary code execution. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector requiring minimal user interaction but no elevated privileges. The attack complexity is low, indicating the exploit is straightforward to execute. The flaw poses high severity across confidentiality, integrity, and availability impacts, making successful exploitation a significant risk for affected organizations. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hotlists. EPSS data indicates minimal prevalence compared to other CVEs, and no public exploit code is currently available, reducing immediate risk but warranting timely patching of affected LabVIEW installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022CPE matchmatch criteria | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* | ||
2023CPE matchmatch criteria | cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.