logo

Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available

ID: e4b2faed-9bde-5e7e-b40c-1f14e6b653b2

STIX ID: report--e4b2faed-9bde-5e7e-b40c-1f14e6b653b2

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

Notepad++ v8.9.7 patch release addresses several high-impact vulnerabilities — notably a PowerShell command injection in the installer, a stack buffer overflow (CVE-2026-54758), a Zip Slip path traversal in the updater (CVE-2026-57233), and session/macro integrity bypasses (including CVE-2026-52886) — which could enable arbitrary code execution, file overwrite, or memory corruption; the vendor recommends immediate updates and verifying download sources while the auto-updater rolls out.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.