PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73250 notepad-plus-plus CVE debrief

A vulnerability in Notepad++ prior to version 8.9.7 allows for command execution in the installer's security context when the context menu component is selected, due to improper handling of the installation directory path. This issue arises from the Notepad++ Windows 11 x64 and ARM64 installer passing the attacker-influenced installation directory to a PowerShell command. The vulnerability poses a risk to Windows systems with Notepad++ installed, as it could allow attackers to execute commands in the installer's security context. Defenders should assess exposure to this vulnerability and prioritize remediation for Notepad++ installations prior to version 8.9.7. The vulnerability is

Vendor
notepad-plus-plus
Product
Unknown
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for managing software installations and security configurations on Windows systems should assess exposure to this vulnerability and prioritize remediation for Notepad++ installations prior to version 8.9.7.

Why it matters

This vulnerability allows for command execution in the installer's security context, posing a risk to Windows systems with Notepad++ installed. Defenders should prioritize verifying the version of Notepad++ and upgrading to version 8.9.7 or later.

  • Verify Notepad++ version and upgrade to 8.9.7 or later.
  • Review installation directories for potential security risks.
  • Assess exposure of Notepad++ installations to command execution.

Technical summary

The Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory to a PowerShell command, allowing for command execution in the installer's security context when the context menu component is selected. This vulnerability is caused by improper handling of the installation directory path, which can be influenced by an attacker. The issue is fixed in version 8.9.7, and defenders should prioritize verifying the version of Notepad++ installed on their systems and upgrading to version 8.9.7 or later to mitigate this vulnerability. The vulnerability affects Notepad++ installations on Windows systems, and defenders should review installation directories for potential security risks

Defensive priority

Defenders should prioritize verifying the version of Notepad++ installed on their systems and upgrading to version 8.9.7 or later to mitigate this vulnerability.

Recommended defensive actions

  • Verify the version of Notepad++ installed on your systems.
  • Upgrade to version 8.9.7 or later.
  • Review installation directories for potential security risks.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The vulnerability is caused by the Notepad++ Windows 11 x64 and ARM64 installer passing the attacker-influenced installation directory to a PowerShell command, allowing for command execution. This issue is fixed in version 8.9.7.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73250 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73250

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73250 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73250

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.