PatchSiren

notepad-plus-plus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH notepad-plus-plus CVE published 2026-06-26

CVE-2026-48800

CVE-2026-48800 is a high-severity vulnerability in Notepad++ that allows for command injection. The vulnerability exists in the way Notepad++ handles user-defined commands in the shortcuts.xml file. An attacker can exploit this vulnerability by injecting malicious commands, which can then be executed when the user clicks on the corresponding entry in the Run menu. This vulnerability has been fixed in Note [truncated]

HIGH notepad-plus-plus CVE published 2026-06-26

CVE-2026-46710

Notepad++ versions 8.9.4 through 8.9.6 contain a local privilege escalation vulnerability. The installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu directory. If an attacker can pre-place a malicious powershell.exe in a user-writable custom installation directory, and a privileged user later runs the installer and selects that [truncated]