National Instruments maintains a focused portfolio of engineering design, simulation, and data-acquisition software used widely in research, industrial control, and embedded systems development. Despite the modest product count, the vendor's prominence in the critical infrastructure and embedded systems landscape means its vulnerabilities have broad downstream reach. The recurring exposure centers on memory-safety issues such as out-of-bounds writes and reads, improper index validation, and path-traversal weaknesses across products including LabVIEW, DAQmx, Circuit Design Suite, VeriStand, and FlexLogger—threat classes typical of native-code instruments and design tools that process untrusted files and configuration inputs. Defenders tracking this vendor should prioritize inventorying integrated systems and automated test platforms that depend on these design tools, as patching often requires coordinated engineering workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by National Instruments over time
Of all the CVEs published by National Instruments as a CNA, 89.2% affect products that National Instruments develops as a vendor.
Of all the CVEs published that affect products developed by National Instruments, 82.2% are self-published by National Instruments as a CNA.
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2449HIGH NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected inst | Mar 18, 2025 | 8.8 | 41 | NO | NO |
CVE-2026-48137CRITICAL There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentiall | Jun 19, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-9142CRITICAL There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthent | Jun 19, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-8036HIGH Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects | Jun 2, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-48139HIGH There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Succ | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-48138HIGH There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requi | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2024-6793CRITICAL A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker | Jul 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-6806CRITICAL The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affect | Jul 22, 2024 | 9.8 | 29 | NO | NO |
CVE-2013-5022HIGH Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and | Aug 6, 2013 | 10.0 | 29 | NO | NO |
CVE-2026-48141HIGH There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion. This affects NI grpc-device 2.17.0 and prior versions. | Jun 19, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by National Instruments.
Media articles that mention a CVE ID that affects a product developed by National Instruments — matched by CVE ID, not by vendor name.