logo

Notepad++ Vulnerability Allows Attackers to Crash Application and Leak Memory Data

ID: c77d0c2a-d736-587f-adcf-7447eb34b3e4

STIX ID: report--c77d0c2a-d736-587f-adcf-7447eb34b3e4

Feed Name: Cyber Press

Threat Score
60/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: AnuPriya

...
...

A format string injection vulnerability (CVE-2026-3008) in Notepad++ 8.9.3's handling of nativeLang.xml can be triggered via the Find in Files/Find ALL features, allowing crashes and memory disclosure (potentially defeating ASLR). The issue requires an attacker to replace a user’s nativeLang.xml (e.g., via social engineering or untrusted files); Notepad++ 8.9.4 patches the flaw and users are urged to update immediately and validate configuration files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.