CVE-2026-9142Disclosure(ni / instrumentstudio)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ni instrumentstudio systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthenticated user access to the server on the local network.  This affects NI grpc-device 2.17.0 and prior versions.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • instrumentstudio
  • ni_grpc_device_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
instrumentstudioni_grpc_device_server

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-19: 2Mentions · 2026-06-20: 1Active Exploitation · 2026-06-20: 1Patch / Workaround · 2026-06-20: 1Technical Details · 2026-06-19: 206-1906-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure2
2026-06-201
Patch1
Full discourse3 posts
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Recent CVEs (June 19): urllib3 DoS (CVE-2026-9375) & NI grpc-device auth bypass (CVE-2026-9142) threaten data privacy/integrity. Zero-days in Chrome, Oracle, OWA also exploited. Patch now! #Cybersecurity #Vulnerabilities #News

    Post summary

    The tweet announces recent CVEs with active exploitation claims and urges users to apply the available patch.

    0000058
    14 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9142 Unauthenticated Access in NI grpc-device 2.17.0 via Insecure Default Credentials https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9142

    Post summary

    The entry announces CVE-2026-9142, describing unauthenticated access in NI grpc-device 2.17.0 due to insecure default credentials, but provides no PoC, exploit, patch, or active exploitation evidence.

    0000044
    4.1K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-9142 - Critical RCE in Ni grpc-device. Insecure default credentials allow unauthenticated network access. #CVSS 9.1. Update immediately. #infosec #cybersecurity #hackers #hacked #100daysofcode #git #github #gitlab https://www.valtersit.com/cve/CVE-2026-9142/

    Post summary

    The post announces a critical RCE in Ni grpc-device (CVE‑2026‑9142) caused by insecure default credentials and urges an immediate update, but provides no PoC, exploit code, or detailed patch information.

    0000052
    947 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appniinstrumentstudio---
Appniinstrumentstudio2026--
Appniinstrumentstudio2026--
Appnini_grpc_device_server---

Explore more