Notepad++ Vulnerability Allows Attackers to Crash Application and Leak Memory Data
ID: c77d0c2a-d736-587f-adcf-7447eb34b3e4
STIX ID: report--c77d0c2a-d736-587f-adcf-7447eb34b3e4
Feed Name: Cyber Press
Threat Score
A format string injection vulnerability (CVE-2026-3008) in Notepad++ 8.9.3's handling of nativeLang.xml can be triggered via the Find in Files/Find ALL features, allowing crashes and memory disclosure (potentially defeating ASLR). The issue requires an attacker to replace a user’s nativeLang.xml (e.g., via social engineering or untrusted files); Notepad++ 8.9.4 patches the flaw and users are urged to update immediately and validate configuration files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
