ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48778
Notepad++ is a free and open-source source code editor.

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature check. When the user triggers IDM_FILE_OPEN_CMD (File → Open Containing Folder → cmd), NppCommands.cpp:228 creates a Command object with this value and calls run(), which invokes ShellExecute (RunDlg.cpp:221) with the attacker-controlled string as the executable path. This vulnerability is fixed in 8.9.6.1.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2026-6539
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and informat

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.

NVD description · AI analysis pending
4.6<1%
  • notepad-plus-plus notepad\+\+
CVE-2026-5525
A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component.

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).

NVD description · AI analysis pending
7.8<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2026-25926
Notepad++ is a free and open-source source code editor.

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application. Version 8.9.2 patches the issue.

NVD description · AI analysis pending
7.3<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2025-15556
Unverified updates in Notepad++ WinGUp updater allow arbitrary code execution

Notepad++ versions prior to 8.8.9, when using the bundled WinGUp updater, download update metadata and installers without cryptographically verifying their integrity (CWE-494). An attacker who can intercept or redirect the updater's network traffic, such as through a man-in-the-middle position or a DNS hijack, can substitute an attacker-controlled installer that the updater then downloads and executes. Successful exploitation yields arbitrary code execution with the privileges of the user running Notepad++, with no attacker credentials or privileges required. Any Windows installation of Notepad++ with the auto-updater in use is affected, and because Notepad++ is one of the most widely used free Windows text editors the potentially exposed population is very large, although practical attacks require control of the victim's update path. CISA added CVE-2025-15556 to the Known Exploited Vulnerabilities catalog on 2026-02-12, and public reporting indicates the hijacked update mechanism was used to deliver targeted malware, confirming exploitation in the wild.

Do: Upgrade to Notepad++ 8.8.9 or later, which adds integrity verification of downloaded updates; this is also the required remediation for federal agencies under CISA BOD 22-01 following the 2026-02-12 KEV listing. Until patched, restrict or monitor hosts' access to the Notepad++ update endpoint and check whether WinGUp recently executed any unexpected installers on systems of interest.

7.72% KEV
  • Notepad++ (notepad-plus-plus) Notepad++ all versions prior to 8.8.9 (Windows, when the bundled WinGUp updater is in use)
masstens of millions of Windows installations (order-of-magnitude estimate)
CVE-2023-47452
+1 in the same advisory: …6401
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working dire

An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

NVD description · AI analysis pending
7.8<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2023-40031
+3 in the same advisory: …40164 …40166 …40036
Notepad++ is a free and open-source source code editor.

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2022-31902
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

NVD description · AI analysis pending
5.5<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2022-31901
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

NVD description · AI analysis pending
6.51% PoC
  • notepad-plus-plus notepad\+\+
CVE-2022-32168
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbi

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

NVD description · AI analysis pending
7.8<1% PoC
  • notepad-plus-plus notepad\+\+
CVE-2019-16294
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.

SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.

NVD description · AI analysis pending
7.810% PoC
  • notepad-plus-plus notepad\+\+
  • notepad-plus-plus scintilla