CVE-2026-6539Disclosure(notepad-plus-plus / notepad\+\+)

LOWCVSS 4.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch notepad-plus-plus notepad\+\+ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-134

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad\+\+

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
notepad\+\+

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-07: 1Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-25: 104-3005-0105-0705-25
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-301
Disclosure1
2026-05-011
Disclosure1
2026-05-071
Disclosure1
2026-05-251
Patch1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Patch

    A patch (v8.9.4) was released within hours of disclosure, addressing both CVE-2026-3008 and a related flaw (CVE-2026-6539). TL;DR Notepad++ version 8.9.3 contains a format string injection flaw (CVE-2026-3008) in the FindInFiles feature that allows attackers to crash the…

    Post summary

    The text announces a quickly released patch for CVE‑2026‑3008 and provides basic technical details about a format‑string injection flaw, with no evidence of exploitation or PoC.

    1000048
    227 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Notepad++ の脆弱性 CVE-2026-3008 が FIX:FindInFiles 機能の不備によるクラッシュと情報漏洩 https://iototsecnews.jp/2026/04/27/notepad-vulnerability-allows-attackers-to-crash-application-leak-memory-data/ Notepad++ の脆弱性 CVE-2026-3008 は、検索機能の内部で設定ファイルを読み込む際の不備が原因で発生しています。具体的には、設定ファイル内の特定の場所に、プログラムが予期しない動作をしてしまう文字列が含まれていると、メモリを正しく処理できなくなります。 CVE-2026-6539 も含め、こうしたメモリに関わる問題は、単なるアプリの強制終了だけでなく、システムの重要な情報を盗み出す手がかりとして悪用される恐れがあります。ご利用のチームは、ご注意ください。 #CVE20263008 #Notepad #Vulnerability

    Post summary

    The article announces the Notepad++ vulnerability CVE‑2026‑3008, describing a FindInFiles feature flaw that causes crashes and memory‑based information leakage, but it does not provide PoC, exploit details, or patch information.

    0100082
    487 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6539 Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disc… https://www.cve.org/CVERecord?id=CVE-2026-6539

    Post summary

    Notepad++ 8.9.3 is affected by CVE-2026-6539, a format string injection flaw that can cause denial of service and information disclosure.

    00010115
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6539 Format String Injection in Notepad++ 8.9.3 Find Results Panel Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6539

    Post summary

    The post announces the discovery of a Format String Injection vulnerability (CVE‑2026‑6539) in Notepad++ 8.9.3, providing a link to vulnerability details but not offering PoC, exploit code, or patch information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnotepad-plus-plusnotepad\+\+8.9.3--

Explore more