PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77605 notepad-plus-plus CVE debrief

A vulnerability in Notepad++ prior to version 8.9.8 allows for the execution of a command script when a user invokes the 'Run by system' action on a text file. An attacker can exploit this by placing a command script with a name that matches the selected text-file path with '.cmd' appended. This issue is resolved in Notepad++ version 8.9.8. The vulnerability is related to the Folder as Workspace 'Run by system' action in Notepad++, which can resolve a different sibling file than the file selected by the user. This can lead to the execution of arbitrary command scripts, elevation of privileges through user interaction, and possible lateral movement within a compromised network.

Vendor
notepad-plus-plus
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-28
Advisory published
2026-09-22
Advisory updated
2026-09-28

Who should care

Defenders and users of Notepad++ should be aware of this vulnerability and take necessary precautions to mitigate it. This includes updating to version 8.9.8 or later and exercising caution when using the 'Run by system' action on text files.

Why it matters

This vulnerability in Notepad++ can lead to the execution of command scripts when a user interacts with a maliciously crafted file. Defenders should prioritize updating Notepad++ and monitoring user interactions to mitigate this risk.

  • Potential execution of arbitrary command scripts
  • Elevation of privileges through user interaction
  • Possible lateral movement within a compromised network
  • Need for verification of Notepad++ version and user interactions

Technical summary

The Folder as Workspace 'Run by system' action in Notepad++ can resolve a different sibling file than the file selected by the user. An attacker can place a command script whose name is the selected text-file path with '.cmd' appended, and the user invokes 'Run by system' on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file.

Defensive priority

Defenders should prioritize updating Notepad++ to version 8.9.8 or later to mitigate this vulnerability. Users who cannot update immediately should exercise caution when using the 'Run by system' action on text files.

Recommended defensive actions

  • Update Notepad++ to version 8.9.8 or later
  • Exercise caution when using the 'Run by system' action on text files
  • Monitor for suspicious activity related to Notepad++ usage
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD vulnerability detail provide information on the vulnerability. The Notepad++ GitHub repository and official website also offer insights into the issue and its resolution. The vulnerability was reported by a researcher and fixed by the Notepad++ development team. The fix is available in version 8.9.8. Users should verify their Notepad++ version and update to 8.9.8 or later to mitigate this vulnerability. The CVE record and NVD detail provide additional information on the vulnerability and its impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77605 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77605

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77605 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77605

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.