08-28-2026 10:05 AM
About a year ago, while I was working at the Section on Instrumentation for the National Institute for Mental Health (part of the NIH), we started getting notices from the IT Security team at NIH saying some particular component of our LabVIEW installation had a security vulnerability, and we should install a particular update to fix it. We had about 4-6 PCs so affected, so I made the rounds, applying the recommended patches (or simplying removing LabVIEW if, say, it was 2018 and the user hadn't used it in the last 5 years).
Security reports were run on Mondays, so it took a while to find out if our patches "fixed the problem". IT Security, of course, didn't know anything about LabVIEW, but most of the time, the "recommended fix" worked, and if it didn't, I just "tried again".
In one case, where the User had installed LabVIEW himself, nothing seemed to work. I convinced him to let me do an "Uninstall/Reinstall" procedure (which took multiple "visits"), but we finally "seemed to be OK". But we still didn't know where these "security notices" were coming from, nor where to turn.
I'm now back in Academia, where "security" is also an issue. Curiously, we are not getting notices about our "unsafe" installations. By following this thread, I've been learning a lot, and am presently removing and then reinstalling the versions of LabVIEW my team and I are currently using (LabVIEW 2024 and 2025), but first installing LabVIEW 2026 Q3 to get the latest Security patches in the system. I'm doing my own machines first, then will try to contact the IT Security team here and share my experiences.
Bob Schor
Professor Emeritus
08-28-2026 11:02 AM - edited 08-28-2026 11:02 AM
@PinguX wrote:
...
Does the CVE-2026-18485, combined with one of the 8 news CVE, allow anyone to gain privileged access to our computer if we make the mistake of downloading and opening a VI that a forum member has uploaded to seek help ?
Or download community packages from VI Package Manager ?
In theory, yes. We do not know of any exploit that attempts to do this, but because it is theoretically possible, we are urging customers to update.
For all those news vulnerabilities, security updates are available for Q3 of LabVIEW 2023/2024/2025/2026.
If I'm still using LabVIEW 2022 or prior, am I screwed ?
Is a perpetual license equivalent to a three-year term if I cannot receive critical security updates ?
Unfortunately, we only support so many back-versions of LabVIEW. I know it won't help you with LabVIEW 2022, but we did recently announce we are extending the support periods for LabVIEW an additional year: Software Product Lifecycle Policies - NI. Future support periods for perpetual will be five years from release.
For your case, we generally try to provide additional guidance on ways to mitigate the issues if you can't update. For the specific use case you mentioned, don't open VIs from untrusted sources, and never open VIs with an account that has admin privileges. While that can't completely eliminate the possibility of exploitation, it greatly reduces it.
08-28-2026 11:04 AM
I just want acknowledge all of the useful feedback on this thread. I appreciate the difficulties that everyone has shared here and our development teams are looking into the various issues discussed.
08-28-2026 12:32 PM
@Evan_C wrote:
I just want acknowledge all of the useful feedback on this thread. I appreciate the difficulties that everyone has shared here and our development teams are looking into the various issues discussed.
FWIW, I'm appreciative you made this post and are getting feedback. Keeping all of this stuff straight is a huge undertaking, especially when trying to juggle several years of different versions across multiple OS's.
I'm very interested in actively helping with this if there's anything I can do. I hope my post earlier doesn't come across as too confrontational. It's an annoying process, sure, but i know you guys are working on it, so I really meant it as a "reality" of what I had to do to implement the patch on my system.
I know all too well how users can fight with issues for YEARS (literally!) before they finally tell me "Hey, can you change XYZ?". Sometimes it's a change I can make in an hour, and all they had to do was tell me about the pain point! 🙂
08-29-2026 07:53 AM
@PinguX wrote:
If I'm still using LabVIEW 2022 or prior, am I screwed ?
Is a perpetual license equivalent to a three-year term if I cannot receive critical security updates ?
With a perpetual license you can still run LabVIEW 2022 even today. If you should do so depends on your security model, network setup and personal behavior in terms of running untrusted software.
With a software lease you simply can't run it anymore once your lease expires. Definitely not the same thing!
08-29-2026 11:27 AM - edited 08-29-2026 11:29 AM
Hi
Just a warning.
I installed NI-PAL 2026 Q3 into Windows 10 2019 ( aka 1809 LTSC ). It is still getting some kind of updates. And running LabVIEW 2019 SP1.
This requires using the NI-PAL 2026 Q3 Update Service version or the extracted 2026 Q3 NIPKG version to avoid other installations like NI-VISA 2026 Q3 which does not work.
So, NI-PAL installed and everything was nice for an hour or so. Then the computer froze. A few reboots later, including a sudden shutdown, I figured out I had a problem.
Restoring the disk to the state before NI-PAL was updated re-established the normally reliable computer operation.
NI-PAL is a Ring-0 driver so something down there was obviously not happy with that newest version.
Regards
08-31-2026 03:30 AM - edited 08-31-2026 03:31 AM
@Evan_C wrote:
For all those news vulnerabilities, security updates are available for Q3 of LabVIEW 2023/2024/2025/2026.
If I'm still using LabVIEW 2022 or prior, am I screwed ?
Is a perpetual license equivalent to a three-year term if I cannot receive critical security updates ?
Unfortunately, we only support so many back-versions of LabVIEW. I know it won't help you with LabVIEW 2022, but we did recently announce we are extending the support periods for LabVIEW an additional year: Software Product Lifecycle Policies - NI. Future support periods for perpetual will be five years from release.
Well, moving away from a 6 month release cycle, shifting to a hybrid approach of LTS LabVIEW every few of years plus "cutting-edge" intermediate releases annually would allow cutting down on the number of versions to support and allow NI to actually offer support for more years. But this has been repeatedly suggested by the community and declined by NI.
Specifically with the introduction of the CRA, the fact that NI only offers support for a few years essentially kills our product life cycle. It will in future be legally irresponsible for us to maintain any software built on a 5-year old LabVIEW version.
The problem of "so many back versions" is home-made. Extending the amount of time covered by "so many" can be changed by NI. Versions less often, same number of supported versions, longer peace of mind for developers and also less churn with releases internally within NI. Seems like a no-brainer.
08-31-2026 09:39 AM
I recently tried to "patch" my personal Laptop by installing LabVIEW 2026 Q3 (64-bit). I previously had 2024 Q3 (64-bit) installed, and things were going well. I don't (now) remember what I decided "went wrong", but I "guessed" it was installing a more-recent version (2026) on top of a previously-working version (2024). So I tried "Uninstall NI Software" and then re-install "newest first", i.e. 2026, then 2024.
Something went wrong, and I now have a Laptop that won't boot. I'm shortly taking it to my local "Computer Repair" center in the hopes they can extract the contents of my hard drive, "build" a new bootable hard drive for me and restore (most of) my files, or whether I'll need to simply purchase a new Laptop and try and restore from the last "image" backup (which consists of a copy of C:*.* to USB drive as D:"Backup <date>").
Bob Schor
08-31-2026 09:43 AM
@Bob_Schor wrote:
[...]
So I tried "Uninstall NI Software" and then re-install "newest first", i.e. 2026, then 2024.
[...]
This order is usually a source of joy
08-31-2026 09:51 AM
@Bob_Schor wrote:
Something went wrong, and I now have a Laptop that won't boot.
Bob Schor
Wow Bob. You are the poster child of unlucky installs! That must be the 4th or 5th unique horror story I have read about your unlucky LV installs.