CVE-2026-25926Disclosure(notepad-plus-plus / notepad\+\+)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for notepad-plus-plus notepad\+\+ systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application. Version 8.9.2 patches the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad\+\+

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
notepad\+\+

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-20: 2Mentions · 2026-02-24: 1PoC Mentioned / Linked · 2026-02-20: 2Exploit Tool / Code · 2026-02-20: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-24: 102-1902-2002-24
Signal classification2 categories
Disclosure
360.0%
PoC
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-202
PoC2
2026-02-241
Disclosure1
Full discourse5 posts
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️#Notepad++: disponibile un #PoC per lo sfruttamento della CVE-2026-25926 che interessa il noto editor di testo Rischio: 🔴 Tipologia: 🔸Arbitrary Code Execution 🔗 https://www.acn.gov.it/portale/w/notepad-poc-pubblico-per-lo-sfruttamento-della-cve-2026-25926 🔄 Aggiornamenti disponibili 🔄

    Post summary

    A PoC for CVE‑2026‑25926, enabling arbitrary code execution in Notepad++, is available and linked, with no indication of current live exploitation or patches.

    0000138
    605 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-25926 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-25926 #CVE-2026-25926 #CVE #High #CyberSecurity #InfoSec https://t.co/CbSTMK2VmV

    Post summary

    A new CVE (CVE-2026-25926) with a severity score of 7.3 and high risk level is announced, but the post lacks detailed technical information, patches, or exploitation evidence.

    0001048
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25926 Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explore… https://www.cve.org/CVERecord?id=CVE-2026-25926

    Post summary

    The post announces an Unsafe Search Path vulnerability (CWE‑426) in Notepad++ versions before 8.9.2, linking to the CVE record.

    00000204
    56.5K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️#Notepad++: disponibile un #PoC per lo sfruttamento della CVE-2026-25926 che interessa il noto editor di testo Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔗 https://www.acn.gov.it/portale/w/notepad-poc-pubblico-per-lo-sfruttamento-della-cve-2026-25926 🔄 Aggiornamenti disponibili 🔄 https://t.co/HJxrhyfWzB

    Post summary

    A PoC for CVE-2026-25926 affecting Notepad++ is publicly available, indicating arbitrary code execution potential, but no exploit code, patch, or active exploitation reports are provided.

    0000033
    605 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25926 Notepad++ Unsafe Search Path Vulnerability Enables Arbitrary Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25926

    Post summary

    Notepad++ CVE-2026-25926 is disclosed as an unsafe search path vulnerability that allows arbitrary code execution; no PoC, exploitation, or patch details are provided.

    0000062
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnotepad-plus-plusnotepad\+\+---

Explore more