Answer in brief
CVE-2026-16233 records a Unknown severity vulnerability in Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI. The current sources do not mark it as known exploited. The current feed maps NI/LabVIEW (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps NI/LabVIEW (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| NI/LabVIEWgeneric | >=0 <23.0.0 || >=23.1.0 <23.3.10 || >=24.1.0 <24.3.7 || >=25.1.0 <25.3.5 || >=26.1.0 <26.3.1 | 23.0.0, 23.3.10, 24.3.7, 25.3.5, 26.3.1 |
Published upstream
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 25, 2026
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
Quoted source text, attributed separately from HOL analysis.