CVE-2026-85995
- EPSS 0.12%
- Veröffentlicht 22.09.2026 17:15:05
- Zuletzt bearbeitet 23.09.2026 18:28:25
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode ...
CVE-2026-86056
- EPSS 0.16%
- Veröffentlicht 22.09.2026 17:14:13
- Zuletzt bearbeitet 23.09.2026 18:28:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members with...
CVE-2026-77605
- EPSS 0.19%
- Veröffentlicht 22.09.2026 17:13:21
- Zuletzt bearbeitet 28.09.2026 18:17:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose ...
CVE-2026-86054
- EPSS 0.2%
- Veröffentlicht 22.09.2026 17:12:38
- Zuletzt bearbeitet 28.09.2026 18:17:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDir= into backu...
CVE-2026-85288
- EPSS 0.12%
- Veröffentlicht 22.09.2026 17:11:47
- Zuletzt bearbeitet 26.09.2026 00:16:37
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple Times entry point, calls macroPlayback() without the validatio...
CVE-2026-85279
- EPSS 0.21%
- Veröffentlicht 22.09.2026 17:08:42
- Zuletzt bearbeitet 23.09.2026 18:28:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexerCou...
CVE-2026-71858
- EPSS 0.1%
- Veröffentlicht 17.08.2026 20:16:46
- Zuletzt bearbeitet 09.09.2026 21:11:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal Open in Defaul...
CVE-2026-57233
- EPSS 0.48%
- Veröffentlicht 17.08.2026 20:16:44
- Zuletzt bearbeitet 09.09.2026 21:11:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to ov...
CVE-2026-54758
- EPSS 0.19%
- Veröffentlicht 17.08.2026 20:16:44
- Zuletzt bearbeitet 09.09.2026 21:11:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and ) into the fixed-size wchar_t ...
CVE-2026-52886
- EPSS 0.18%
- Veröffentlicht 17.08.2026 20:16:44
- Zuletzt bearbeitet 09.09.2026 21:11:25
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, allowing parent...