
A patch (v8.9.4) was released within hours of disclosure, addressing both CVE-2026-3008 and a related flaw (CVE-2026-6539). TL;DR Notepad++ version 8.9.3 contains a format string injection flaw (CVE-2026-3008) in the FindInFiles feature that allows attackers to crash the…
Post summary
The text announces a quickly released patch for CVE‑2026‑3008 and provides basic technical details about a format‑string injection flaw, with no evidence of exploitation or PoC.



