CVE-2026-18444CWE-195

CVE-2026-18444

Medium · published August 25, 2026

CVSS v3.1
6.6
EPSS
0%
Percentile
2.3
In the wild
Unconfirmed
What it is

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI file.  This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.

The record
Technical detail
CVSS v3.1
6.6 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CVSS v4.0
6.9 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS
0.00122 · 2.3th percentile
Weakness
CWE-195 · Signed to Unsigned Conversion Error
Published
2026-08-25T21:17Z
References (1)
EPSS history
Timeline
  • 27 AUG 06:20Z
    EPSS moved — → 0%
    epss
  • 25 AUG 16:09Z
    Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
    cvelistv5