These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Notepad++ prior to version 8.9.8 allows for the execution of tampered macros through the multi-run dialog, potentially leading to the invocation of internal Notepad++ commands or external programs in the current user context. This issue arises because Notepad++ incompletely enforces shortcuts.xml HMAC validation, specifically through the WM_MACRODLGRUNMACRO entry point, which calls macr [truncated]
A vulnerability in Notepad++ prior to version 8.9.7 allows macros loaded from an attacker-controlled shortcuts.xml to bypass HMAC validation and invoke certain actions in an elevated process, potentially leading to protected file modification and elevated command execution. This issue affects users who open files from untrusted sources, especially in environments where Notepad++ is used. The vulnerability [truncated]
A vulnerability in Notepad++ prior to version 8.9.7 allows for code execution when loading a malicious plugin. The issue arises from the WinGup decompress function not properly validating ZIP entry names, which can lead to overwriting DLL files in sibling plugin directories. This vulnerability can be exploited by attackers to execute arbitrary code, potentially leading to system compromise. Users of Notep [truncated]
A vulnerability in Notepad++ prior to version 8.9.7 allows for a stack buffer overflow, potentially leading to process termination and code execution. This issue is fixed in version 8.9.7. The vulnerability exists in the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp, where a Notepad++ variable name is copied between $( and ) into a fixed-size wchar_t str[M [truncated]
CVE-2026-52886 debrief based on the supplied source corpus. Notepad++ versions prior to 8.9.7 are vulnerable to arbitrary file reads during snapshot-mode restoration due to improper validation of the backupFilePath attribute. This issue allows defenders to assess exposure and verify installations. The vulnerability has been fixed in version 8.9.7, and defenders should prioritize verifying Notepad++ instal [truncated]
A vulnerability in Notepad++ prior to version 8.9.7 allows for command execution in the installer's security context when the context menu component is selected, due to improper handling of the installation directory path. This issue arises from the Notepad++ Windows 11 x64 and ARM64 installer passing the attacker-influenced installation directory to a PowerShell command. The vulnerability poses a risk to [truncated]
CVE-2026-48800 is a high-severity vulnerability in Notepad++ that allows for command injection. The vulnerability exists in the way Notepad++ handles user-defined commands in the shortcuts.xml file. An attacker can exploit this vulnerability by injecting malicious commands, which can then be executed when the user clicks on the corresponding entry in the Run menu. This vulnerability has been fixed in Note [truncated]
Notepad++ versions 8.9.4 through 8.9.6 contain a local privilege escalation vulnerability. The installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu directory. If an attacker can pre-place a malicious powershell.exe in a user-writable custom installation directory, and a privileged user later runs the installer and selects that [truncated]