Two high-severity arbitrary code execution vulnerabilities (CVE-2026-48778 and CVE-2026-48800, CVSS 7.8) have been discovered in Notepad++ affecting all versions up to 8.9.6. Both flaws exploit the editor's XML configuration files — shortcuts.xml and config.xml — which store user-defined commands and the command-line interpreter path without any validation. A local attacker who can write to these files can inject malicious executables that survive reboots and blend into the Run menu as legitimate-looking entries. A third lower-severity crash bug (CVE-2026-48770, CVSS 5.0) was also patched. All three were fixed in version 8.9.6.1, released the same day as disclosure. Users are advised to monitor AppData for unexpected changes to the affected XML files, as the attack leaves no trace in the installation directory or binary.

4m read timeFrom csoonline.com
Post cover image
438 Impressions