CVE-2026-34401Disclosure(microsoft / xml_notepad)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes XML Notepad to make outbound HTTP/SMB requests, potentially leaking local file contents or capturing the victim's NTLM credentials. This issue has been patched in version 2.9.0.21.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xml_notepad

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-31); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
xml_notepad

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Technical Details · 2026-03-31: 103-3104-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-011
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-34401 XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does n… https://www.cve.org/CVERecord?id=CVE-2026-34401

    Post summary

    The text references CVE-2026-34401 with minimal context and lacks detailed information on the vulnerability or exploitation.

    00000111
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-34401: XML Notepad: XML External Entity... XXE in XML Notepad enables NTLM credential theft via malicious DTD—drop a crafted XML file and watch SMB auth fly to yo... https://zerodaysignal.com/vulnerability/CVE-2026-34401 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The brief note discloses CVE-2026-34401, an XXE flaw in XML Notepad that can lead to NTLM credential theft, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000061
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftxml_notepad-windows-

Explore more