Categories: Cyber Security News

Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data

A security vulnerability has been identified in Notepad++, one of the most widely used open-source text editors among developers and IT professionals.

The vulnerability CVE-2026-3008, which could allow a remote attacker to crash the application or extract sensitive memory address information from affected systems.

The vulnerability is a string injection flaw located within the FindInFiles functionality of Notepad++. Specifically, the issue arises when the nativeLang.xml configuration file’s "find-result-hits" field contains a "%s" format specifier, triggering unexpected behavior during search operations.

This type of vulnerability can lead to improper memory handling, enabling threat actors to either cause a denial-of-service (DoS) condition by crashing the application or gather memory address information that could be leveraged in further exploitation attempts.

The second one, CVE-2026-6539, has also been linked to the same patch, suggesting additional related security concerns were addressed alongside the primary vulnerability.

Successful exploitation could disrupt workflows for developers, system administrators, and security analysts who rely on Notepad++ for day-to-day operations.

Memory disclosure vulnerabilities, while sometimes considered low-severity in isolation, are often chained with other exploits to bypass security mitigations such as Address Space Layout Randomization (ASLR).

Affected Version

The vulnerability specifically affects:

  • Notepad++ version 8.9.3

Users running earlier versions should assume they are equally at risk and apply the available patch without delay.

Patch Released

The Notepad++ Product Owner Mr Hazley Samsudin, has responded promptly by releasing version 8.9.4, which directly addresses both CVE-2026-3008 and CVE-2026-6539.

The fix resolves the crash behavior in the FindInFiles feature when format strings are improperly parsed from the nativeLang.xml file. The patch details are publicly documented on the official Notepad++ GitHub repository under issue #17960.

Mitigations

CSA strongly advises all users and administrators running the affected version to take the following action immediately:

  • Update to Notepad++ version 8.9.4 via the official Notepad++ website or the built-in update mechanism
  • Verify the integrity of the downloaded installer using official checksums
  • Monitor systems for any unusual application behavior that may indicate prior exploitation attempts

Given the widespread deployment of Notepad++ across enterprise environments and developer workstations, organizations should prioritize this update within their standard patch management cycles.

Users who rely on custom nativeLang.xml configurations are particularly urged to apply the fix without delay.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

IMS CARB DAY EXCLUSIVE: Kayla and AG Rokita discuss Secretary of State Race Shakeup

INDIANAPOLIS, IND. (WOWO) Indiana Attorney General Todd Rokita said Thursday that he withdrew his support…

1 second ago

Three-judge panel to rule on NAACP challenge of redrawn Tennessee district map

Anthony Ashton, an attorney representing the NAACP Tennessee State Conference and other plaintiffs in a…

5 minutes ago

Stockard on the Stump: Tennessee, Nashville pour untold resources into Super Bowl LXIV

Former Gov. Bill Haslam and sportscaster Jim Nantz, a Nashville resident, touted the 2030 Super…

5 minutes ago

Sagging poll ratings, soaring gas prices put GOP in a fix for keeping US House control

Missouri Governor Mike Kehoe, left, talks with U.S. Vice President JD Vance after he arrived…

5 minutes ago

Web3 accelerator OnePieceLabs.xyz connects founders with networks, mentorship, and resources for building decentralized technology

OnePieceLabs.xyz – Squarespace customer – (United States) Organizations building at the frontier of decentralized technology…

2 hours ago

Smithfield Foods workers voice excitement for new Sioux Falls plant

May 21, 2026 Inside the century-old Smithfield Foods plant in downtown Sioux Falls, employees say…

2 hours ago

This website uses cookies.