Browse all 84 CVE security advisories affecting NI. AI-powered Chinese analysis, POCs, and references for each vulnerability.
NI develops hardware and software for test, measurement, and control applications, primarily serving engineering and scientific sectors. Its software ecosystem, including LabVIEW and TestStand, facilitates complex data acquisition and automated testing workflows. Historically, the platform has exhibited vulnerabilities ranging from remote code execution and buffer overflows to cross-site scripting and privilege escalation flaws. These issues often stem from legacy codebases and complex integration points within its extensive library of drivers and utilities. While no catastrophic, widespread breaches have defined its public history, the high number of recorded CVEs indicates persistent security challenges in maintaining robust defenses across diverse industrial environments. The company generally responds to disclosures through timely patches, yet the breadth of its product portfolio necessitates rigorous configuration management by users to mitigate risks associated with outdated components or misconfigured systems.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-9143 | Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen — grpc-device CWE-681 | 3.7 | Low | 2026-06-19 |
| CVE-2026-9142 | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present — grpc-device CWE-306 | 9.1 | Critical | 2026-06-19 |
| CVE-2026-48141 | Memory leak in NI grpc-device BeginSidebandStream — grpc-device CWE-401 | 5.3 | Medium | 2026-06-19 |
| CVE-2026-48140 | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream — grpc-device CWE-704 | 6.5 | Medium | 2026-06-19 |
| CVE-2026-48139 | NULL pointer dereference vulnerability in NI grpc-device data moniker service — grpc-device CWE-476 | 7.5 | High | 2026-06-19 |
| CVE-2026-48138 | Out-of-bounds read vulnerability in the NI grpc-device streaming API — grpc-device CWE-125 | 7.5 | High | 2026-06-19 |
| CVE-2026-48137 | Untrusted pointer dereference in NI grpc-device sideband streaming API — grpc-device CWE-822 | 9.1 | Critical | 2026-06-19 |
This page lists every published CVE security advisory associated with NI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.