Critical Security Update

To help protect your systems, customers using NI driver software 2026 Q2 or earlier should visit ni.com/ni-pal-update and follow the recommended actions.

Required NI-PAL Security Update

Overview

To protect customer systems, we recommend all customers using versions of NI-PAL older than Q3 2026 to install a security update. NI-PAL, a component used in many NI drivers, is on the Microsoft vulnerable driver blocklist due to security issues described in CVE-2026-18485. Beginning as early as November 10, 2026, Windows may block affected NI-PAL components from loading when the blocklist is enabled. If the update is not installed, NI software and hardware workflows may stop working after a Windows security update.

 

This targeted update affects only one component. It does not require a driver version upgrade and is backwards compatible with previous NI-PAL versions to at least NI-PAL 17.0.

Contents

Customer Impact of NI-PAL Being Blocked

As early as November 10, 2026, systems that have not been updated will encounter various errors in NI Measurement & Automation Explorer (MAX), NI Hardware Manager, or device drivers.

Who Should Take Action

Customers using NI software or hardware on Microsoft Windows systems should check the installed NI-PAL version. Systems with NI-PAL 26.3.1 or earlier are affected and should be updated. The vulnerable driver blocklist is enabled by default on Windows 11 and is not enabled by default on Windows 10, although settings may have been changed by the customer or IT organization.

Required Actions—Verify NI-PAL Version and Update

  1. Check the installed version—Open %WinDir%\system32\drivers, locate nipalk.sys, open Properties, and review Product Version on the Details tab.
  2. Install the update—If the version is 26.3.1 or earlier, install NI-PAL 2026 Q3 or later using NI Update Service or the offline installer from the NI-PAL download page.
    Note: If you are using NI Update Service, you may need to first update NI Package Manager to see the available update.
  3. Restart the system—The update takes about one minute to install and requires a restart.
  4. Validate operation—After restarting, complete the recommended validation checks below.
    • Confirm the device is available in NI MAX or NI Hardware Manager.
    • Run Device Self-Test and Reset.
    • Run a Test Panel or an example program that uses the hardware.

Additional Guidance

  • We do not recommend disabling the Microsoft vulnerable driver blocklist as a general workaround. Doing so can reduce Windows protection against known vulnerable kernel drivers.
  • No known exploits for CVE-2026-18485 were known at the time of the source announcement.
  • The Windows blocklist is enforced only on Windows systems. Linux customers with the affected NI-PAL component have the same security vulnerability but no deadline to update by for continued successful operations. We encourage Linux customers to also follow the latest security advisories to ensure timely notice of critical and security-relevant NI software updates, and update software as needed to stay secure.
  • Customers should enable NI Update Service notifications and subscribe to NI security advisories for future updates.

Additional Resources

If you have any questions, concerns, or would like to discuss this issue further, please don’t hesitate to reach out to our technical support team. 

Windows is a trademark of the Microsoft group of companies. 
The registered trademark Linux® is used pursuant to a sublicense from LMI, the exclusive licensee of Linus Torvalds, owner of the mark on a worldwide basis.