CVE-2026-48141: Ni Instrumentstudio

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion.  This affects NI grpc-device 2.17.0 and prior versions.

Affected products

  • Ni Instrumentstudio: up to and including 2025; version 2026 only
  • Ni Ni Grpc Device Server: before 2.18.0 (fixed in 2.18.0)

Published 2026-06-19. Last modified 2026-06-25.