Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure
ID: d91fc1b7-fd50-5565-ac92-a350274afff2
STIX ID: report--d91fc1b7-fd50-5565-ac92-a350274afff2
Feed Name: ThreatCluster
Threat Score
**CVE-2026-3008 — Notepad++ 8.9.3 format string injection:** A malicious nativeLang.xml language pack can trigger a format string vulnerability allowing application crash (DoS) and memory disclosure; a PoC was published April 20, 2026 and the issue was disclosed April 27, 2026 — users should upgrade to Notepad++ 8.9.4 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
