Notepad++ Security Updates Fix Three Vulnerabilities Including High-Risk Code Injection (heise.de)
0xBASE INTEL BRIEF
- Two high-severity flaws (CVSS 7.8) allow command injection via config.xml and shortcuts.xml.
- CVE-2026-48770 (CVSS 5.0) enables local DoS via WM_COPYDATA.
- Notepad++ v8.9.6.1 is available for manual download from the project site.
"Notepad++ v8.9.6.1 patches two high-severity vulnerabilities (CVE-2026-48778, CVE-2026-48800) and one medium-severity flaw (CVE-2026-48770). Attackers can inject commands or code via manipulated configuration files or cause a denial of service. The built-in updater does not yet offer the new version; manual download is required."
no comments yet.