logo

Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

ID: d91fc1b7-fd50-5565-ac92-a350274afff2

STIX ID: report--d91fc1b7-fd50-5565-ac92-a350274afff2

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-29

...
...

**CVE-2026-3008 — Notepad++ 8.9.3 format string injection:** A malicious nativeLang.xml language pack can trigger a format string vulnerability allowing application crash (DoS) and memory disclosure; a PoC was published April 20, 2026 and the issue was disclosed April 27, 2026 — users should upgrade to Notepad++ 8.9.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.