PT-2026-35357 · Notepad++ · Notepad++

Hazley Samsudin

·

Published

2026-04-27

·

Updated

2026-05-25

·

CVE-2026-3008

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.4
Description A string injection issue exists in the FindInFiles search function due to flaws in the formatting string processing mechanism. Successful exploitation could allow an attacker to obtain sensitive memory address information or cause the application to crash (denial of service) by using a specially crafted file. This risk is particularly relevant for users utilizing custom nativeLang.xml localization files.
Recommendations Update to version 8.9.4 or later. Avoid using untrusted configuration or localization files.

Exploit

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06063
CVE-2026-3008

Affected Products

Notepad++