CVE-2026-52885General(notepad-plus-plus / notepad\+\+)

LOWCVSS 6.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-Check). However, the command payload is taken from the in-memory _userCommands vector, which is populated at application startup and never re-synchronized with the on-disk file (Time-of-Use). Swapping shortcuts.xml between startup and command execution causes the HMAC check to validate a clean file while a malicious command runs. An attacker with write access to shortcuts.xml places a malicious version on disk before launch, then immediately restores the legitimate file. The HMAC check at execution time validates the restored legitimate file (check passes), while the malicious payload executes from memory. This vulnerability is fixed in 8.9.6.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad\+\+

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
notepad\+\+

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-27: 3Technical Details · 2026-06-27: 106-27
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-52885 Time-of-Check Time-of-Use Vulnerability in Notepad++ Before 8.9.6.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-52885

    Post summary

    A Time-of-Check Time-of-Use vulnerability (CVE-2026-52885) exists in Notepad++ versions older than 8.9.6.4, but the snippet provides only basic technical detail without any proof‑of‑concept, exploit code, patch, or active exploitation evidence.

    00010129
    4.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-52885 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fi… https://www.cve.org/CVERecord?id=CVE-2026-52885

    Post summary

    The note references CVE-2026-52885 and mentions a checksum verification in Notepad++’s shortcuts file, but offers no further technical detail, exploit information, or remediation guidance.

    00010789
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-52885 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fi… https://www.cve.org/CVERecord?id=CVE-2026-52885 ----- Traducción: CVE-2026-52885 Not… http://infoflow.cloud`

    Post summary

    The text merely announces CVE-2026-52885 for Notepad++ and links to the CVE record, providing no evidence of exploits, PoCs, or patches.

    0000041
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnotepad-plus-plusnotepad\+\+---

Explore more