CVE-2026-2538Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolled search path. Attacking locally is a requirement. The attack's complexity is rated as high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-16); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-16: 3Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 2Technical Details · 2026-02-20: 102-1602-20
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-163
Disclosure2General1
2026-02-201
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2538 Uncontrolled Search Path Vulnerability in Flos Freeware Notepad2 4.2.22-4.2.25 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2538

    Post summary

    A vulnerability disclosure for CVE-2026-2538, describing an uncontrolled search path issue affecting Flos Freeware Notepad2 4.2.22‑4.2.25, with no additional exploit or patch details.

    0000133
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2538 (CVSS:7.3, HIGH) is Awaiting Analysis. A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown functi..https://nvd.nist.gov/vuln/detail/CVE-2026-2538 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new vulnerability, CVE-2026-2538, has been identified in Flos Freeware Notepad2 with a high CVSS score, but no PoC, exploit, or patch information is provided.

    0000034
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 High-severity vuln in Notepad2 (v4.2.22 – 4.2.25): Local attackers can hijack DLL search path for code execution — no patch yet! Restrict access & monitor endpoints. Details: https://radar.offseq.com/threat/cve-2026-2538-uncontrolled-search-path-in-flos-fre-d9540b5b #OffSeq ... https://t.co/RHlwlLxtuX

    Post summary

    Notepad2 v4.2.22‑4.2.25 is vulnerable to a DLL search path hijack that can lead to local code execution; no patch is available yet, so restrict access and monitor endpoints.

    0000025
    265 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2538 A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a mani… https://www.cve.org/CVERecord?id=CVE-2026-2538

    Post summary

    The text announces the discovery of CVE-2026-2538 affecting Notepad2 via Msimg32.dll, but lacks details on exploitation, patches, or technical specifics.

    00000375
    56.4K followersView on X

Explore more