Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data
ID: c7574e23-9bc6-5111-824c-03e235eaca49
STIX ID: report--c7574e23-9bc6-5111-824c-03e235eaca49
Feed Name: cybersecurityNews.com
Threat Score
A format-string vulnerability (CVE-2026-3008) in Notepad++'s FindInFiles functionality can cause application crashes or disclose memory addresses when the nativeLang.xml "find-result-hits" field contains a "%s" specifier; a related issue (CVE-2026-6539) was fixed alongside it. Notepad++ 8.9.4 addresses both issues; administrators are advised to update immediately, verify installer integrity, and monitor systems for signs of prior exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
