Have you checked your NI-PAL version yet?
On November 10, 2026, Microsoft will block vulnerable NI-PAL drivers from loading on Windows systems. The Microsoft vulnerable driver blocklist is a Windows security feature that stops kernel drivers with known security flaws from loading, and it is enabled by default on Windows 11. After the corresponding Windows update, unpatched systems will show:
- application failures or timeouts
- driver communication failures
- unspecified errors in NI MAX, NI Hardware Manager and device drivers
In other words: your test stand runs fine on Monday and stops working after Patch Tuesday.
What's going on?
Most of us never think about NI-PAL. It sits quietly underneath NI MAX, DAQmx, VISA and many other NI drivers, handling the kernel-level work so our VIs can talk to hardware.
NI has published a security advisory for a local privilege escalation vulnerability in the NI-PAL kernel driver (CVE-2026-18485, CVSS 3.1 score 7.8 / CVSS 4.0 score 8.5). An authenticated local user could use it to gain elevated privileges on the machine. NI-PAL 26.3.1 and earlier on Windows are affected. Linux systems are not.
How to check your version
Open PowerShell, paste this line and press Enter:
(Get-Item "$env:WinDir\System32\drivers\nipalk.sys").VersionInfo.ProductVersion
If the version shown is 26.3.1 or lower, you need the update.
Prefer clicking? Open %WinDir%\system32\drivers, right-click nipalk.sys, select Properties and check the Product Version on the Details tab.
How to fix it
Install NI-PAL 2026 Q3 or later, either via NI Update Service (listed under Urgent Updates as "NI Core Driver (NI-PAL) 2026 Q3") or with the offline installer from the NI-PAL download page. If NI Update Service doesn't offer the patch, update NI Package Manager first.
The good news:
- Only the NI-PAL core driver is replaced; DAQmx, VISA and your other NI drivers stay on their current versions
- It's backwards compatible with NI-PAL versions down to at least 17.0
- The installation itself takes about one minute (plus a reboot)
Afterwards, confirm your devices show up in NI MAX or NI Hardware Manager, run a Self-Test and Reset, and give your test program a quick run.
What about offline or isolated systems? Machines that don't receive the Windows update won't be interrupted on November 10, but the vulnerability is still there. It surfaces as soon as the system gets connected and updated, or the blocklist is enabled another way. Installing the update remains the safest choice wherever possible.
Find all the details in NI's Update Instructions and the Security Advisory.
Did this tip help you? Please pass it on to your colleagues and #labviewfriends!
Stay tuned for more LabVIEW TotDs!
