National Instruments security advisory (AV26-914)
National Instruments' SystemLink software has two flaws that let attackers bypass security and read sensitive data. Attackers could steal information if they gain access to your network.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Exploited
- Not confirmedNo confirmation recorded
How it works
- Attackers exploit two flaws in SystemLink: one lets them bypass security checks to access parts of the system they shouldn't, and another lets them read sensitive data without encryption.
- Both flaws require attackers to already have network access to your SystemLink server or client.
What to do
If you use National Instruments SystemLink or SystemLink Server, check your installed version by opening the About dialog in the application. Compare it against 2026 Q3 Patch 1 or later.
Run this in the application environment you want to check:
python3 -m pip show ni-systemlinkUpdate to SystemLink 2026 Q3 Patch 2 or later. Check the National Instruments security updates page for the latest instructions.
Technical details
National Instruments disclosed two critical flaws in SystemLink (versions up to and including 2026 Q3 Patch 1) and SystemLink Server (same version). The first, improper access controls, allows unauthorized users to bypass authentication and access restricted system functions, potentially enabling full administrative control. The second, storage of sensitive information in cleartext, exposes credentials, configuration data, and other confidential details in unencrypted logs or files, risking exfiltration by attackers.
Both vulnerabilities were reported to the Canadian Centre for Cyber Security (CCCS) under advisory AV26-914 on September 11, 2026. No CVSS score or CVE ID was assigned in the provided text. Updates are available but not explicitly named.
References
- ni.com · improper-access-controls-in-ni-systemlink.html CCCS Canada
- ni.com · storage-of-sensitive-information-in-cleartext-in-ni-systemlink.html CCCS Canada
- ni.com · 2026.html CCCS Canada