logo

Notepad++ Patches High-Severity RCE Flaws in Version 8.9.6.1

ID: 4f003bfe-665f-5fcf-a312-c248261a4943

STIX ID: report--4f003bfe-665f-5fcf-a312-c248261a4943

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Ashish Khaitan

...
...

Notepad++ released version 8.9.6.1 to patch multiple security vulnerabilities — most critically CVE-2026-48778, an OS command injection in processing config.xml that can lead to remote code execution when users trigger the “Open Containing Folder in cmd” feature. Researchers demonstrated a proof-of-concept and recommend immediate updates and defensive measures to mitigate exploitation paths such as modified AppData config files, crafted shortcuts, and cloud-synced configuration poisoning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.