<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical Notepad++ Flaws Let Attackers Run Malicious Code — Update Now

Update Notepad++ to v8.9.6.1 to patch critical security flaws, including CVE-2026-48778, preventing malicious executable path attacks.
Content Team

Notepad++ has patched three security vulnerabilities in version v8.9.6.1, released May 26, 2026 — two of them critical. The worst, CVE-2026-48778, lets attackers plant a malicious executable path inside Notepad++'s config.xml file. When a user opens a folder via the command line menu, Windows runs the attacker's program instead. No validation, no warning.

A second critical flaw, CVE-2026-48800, works the same way but targets shortcuts.xml. Attack paths include modifying local config files, poisoning cloud-synced settings, or social engineering via archive extraction.

Anyone running v8.9.6 or earlier should update immediately from the official releases page.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo