CVE-2026-48137: Ni Instrumentstudio
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.
Affected products
- Ni Instrumentstudio: up to and including 2025; version 2026 only
- Ni Ni Grpc Device Server: before 2.18.0 (fixed in 2.18.0)
Published 2026-06-19. Last modified 2026-06-25.