CVE-2026-48139
NI grpc-device, InstrumentStudio, instrumentstudio
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Successful exploitation requires an attacker to provide an unknown value to the data moniker service. This affects NI grpc-device 2.17.0 and prior versions.
- CVSS
- 8.7
- EPSS
- 0.49% 39.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.19