Notepad++ Patches High-Severity RCE Flaws in Version 8.9.6.1
ID: 4f003bfe-665f-5fcf-a312-c248261a4943
STIX ID: report--4f003bfe-665f-5fcf-a312-c248261a4943
Feed Name: The Cyber Express
Notepad++ released version 8.9.6.1 to patch multiple security vulnerabilities — most critically CVE-2026-48778, an OS command injection in processing config.xml that can lead to remote code execution when users trigger the “Open Containing Folder in cmd” feature. Researchers demonstrated a proof-of-concept and recommend immediate updates and defensive measures to mitigate exploitation paths such as modified AppData config files, crafted shortcuts, and cloud-synced configuration poisoning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
