PatchSiren cyber security CVE debrief
CVE-2026-73250 notepad-plus-plus CVE debrief
A vulnerability in Notepad++ prior to version 8.9.7 allows for command execution in the installer's security context when the context menu component is selected, due to improper handling of the installation directory path. This issue arises from the Notepad++ Windows 11 x64 and ARM64 installer passing the attacker-influenced installation directory to a PowerShell command. The vulnerability poses a risk to Windows systems with Notepad++ installed, as it could allow attackers to execute commands in the installer's security context. Defenders should assess exposure to this vulnerability and prioritize remediation for Notepad++ installations prior to version 8.9.7. The vulnerability is
- Vendor
- notepad-plus-plus
- Product
- Unknown
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for managing software installations and security configurations on Windows systems should assess exposure to this vulnerability and prioritize remediation for Notepad++ installations prior to version 8.9.7.
Why it matters
This vulnerability allows for command execution in the installer's security context, posing a risk to Windows systems with Notepad++ installed. Defenders should prioritize verifying the version of Notepad++ and upgrading to version 8.9.7 or later.
- Verify Notepad++ version and upgrade to 8.9.7 or later.
- Review installation directories for potential security risks.
- Assess exposure of Notepad++ installations to command execution.
Technical summary
The Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory to a PowerShell command, allowing for command execution in the installer's security context when the context menu component is selected. This vulnerability is caused by improper handling of the installation directory path, which can be influenced by an attacker. The issue is fixed in version 8.9.7, and defenders should prioritize verifying the version of Notepad++ installed on their systems and upgrading to version 8.9.7 or later to mitigate this vulnerability. The vulnerability affects Notepad++ installations on Windows systems, and defenders should review installation directories for potential security risks
Defensive priority
Defenders should prioritize verifying the version of Notepad++ installed on their systems and upgrading to version 8.9.7 or later to mitigate this vulnerability.
Recommended defensive actions
- Verify the version of Notepad++ installed on your systems.
- Upgrade to version 8.9.7 or later.
- Review installation directories for potential security risks.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The vulnerability is caused by the Notepad++ Windows 11 x64 and ARM64 installer passing the attacker-influenced installation directory to a PowerShell command, allowing for command execution. This issue is fixed in version 8.9.7.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73250 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73250
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73250 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73250
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/notepad-plus-plus/notepad-plus-plus/commit/3764d5b72664ef95421bc53bcb204f9b977d346b
-
Source reference
Unverified legacy reference
URL: https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.7
-
Source reference
Unverified legacy reference
URL: https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gp2r-262h-9hgf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.