CVE-2026-48137 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-48137 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-48137 is an untrusted pointer dereference vulnerability in the NI gRPC Device Server's sideband streaming API, affecting NI InstrumentStudio and the NI gRPC Device Server product.
Technical Detail
The flaw exists in the sideband streaming API component of the NI gRPC Device Server, where attacker-controlled data is used as a pointer without proper validation, allowing an arbitrary memory dereference. A remote attacker capable of sending crafted gRPC requests to the affected service could trigger this condition. Successful exploitation may result in remote code execution or process crash, depending on memory layout and attacker capability, earning this vulnerability a CVSS score of 9.1 (Critical).
Exploitation Status
No known exploit exists for this vulnerability at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog. There is no public proof-of-concept code or reported exploitation activity as of June 26, 2026.
Who Is Targeting This
No specific threat actor attribution at this time. No confirmed or reported threat actors have been associated with exploitation of this vulnerability.
What To Do
Organizations running NI InstrumentStudio or the NI gRPC Device Server should apply vendor-supplied patches as soon as they are available and prioritize this update given the Critical severity rating. In the interim, restrict network access to the gRPC Device Server service using host-based firewalls or network segmentation, ensuring the service is not exposed to untrusted networks or the public internet. Monitor service logs for unexpected crashes or anomalous gRPC connection attempts as potential indicators of exploitation attempts. Check the NI security advisory portal for patch availability and version-specific guidance.