There are two invalid input validation vulnerabilities recently discovered in NI-PAL. These vulnerabilities affect NI-PAL 26.3.0 and prior versions on Windows, Linux, and Linux Real-Time.
CVE-2026-8035 may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference.
CVE-2026-8036 may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation.
Many NI drivers include NI-PAL and are affected by these vulnerabilities. Refer to the Mitigation Guidance section for identifying the version of NI-PAL installed and how to upgrade or install the patch.
NI strongly recommends upgrading the affected software to mitigate these vulnerabilities. Refer to the Affected Products section for information on upgrading these products.
NI-PAL is a common component in many NI drivers. You only need to upgrade one NI driver that includes this component or install the patch once per machine. The patch is backwards compatible with previous versions of NI software.
This vulnerability affects NI-PAL 26.3.0 and prior versions. To determine the version of NI-PAL installed, follow the instructions for your operating system.
OR
If the NI-PAL version is 26.3.0 or prior, upgrade the NI driver version.
NI Update Service is a Windows utility that checks for and delivers updates for NI software and drivers, including security updates. It can be used to manually check for updates, configured to periodically check and notify users, or to automatically download and install updates at a scheduled time.
Some mitigations in this advisory are delivered through NI Update Service. NI recommends upgrading to NI Update Service 2026 Q1 or later to get the latest updates. NI Update Service can be installed on its own and is backwards compatible with older NI software.
At NI, we view the security of our products as an important part of our commitment to our customers. Go to ni.com/security to stay informed and act upon security alerts and issues.
NI would like to thank Patrick Saif (@weezerOSINT) for reporting this issue and working with us on coordinated disclosure.
| Product Version | Mitigation |
|---|---|
| NI-PAL 26.3.0 and prior versions | Windows: Install NI-VISA 2026 Q2 Patch 1 (26.3.1) or later from NI Package Manager or Software Downloads or install patch via NI Update Service. |
| Linux Desktop: Install NI Linux Device Drivers 2026 Q2 or later. See mitigation guidance. | |
| NI Linux Real-Time: Install NI Linux RT System Image 2026 Q2 or later. See mitigation guidance. |