Notepad++ disclosed a critical vulnerability affecting version 8.9.3 and earlier, and the Canadian Centre for Cyber Security urged users to apply the vendor’s update. The issue is tracked as CVE-2026-3008 and has been described as a string injection flaw that can let an attacker obtain memory address information or crash the application; the recommended remediation is to upgrade to Notepad++ 8.9.4.
Public CVE records indicate the flaw is remotely reachable with low attack complexity, requires no privileges and no user interaction, and carries high potential impact across confidentiality, integrity, and availability. References tied to the disclosure include Notepad++ release materials, issue-tracking resources, and a Singapore CSA advisory, underscoring broad public disclosure and the need for rapid patching on systems where Notepad++ is installed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-27, Moxa published a security advisory covering CVE-2026-3867 and CVE-2026-3868 in several industrial networking and secure router product lines, including TN-4900, EDR-8010, EDR-G9010, OnCell G4302-LTE4, OnCell G4308-LTE4, and EDF-G1002-BP series. The advisory described improper ownership management and improper handling of length parameter inconsistency issues and identified affected firmware ranges.
On 2026-04-27, a new CVE record for CVE-2026-3008 documented a string injection vulnerability in Notepad++ that could disclose memory address information or crash the application. The entry included a CVSS v4.0 vector and references to public release notes, issue-tracking resources, and external advisories.
On 2026-04-26, Notepad++ published a security advisory for a critical vulnerability affecting version 8.9.3 and earlier, and recommended upgrading to release 8.9.4. The issue was later associated with CVE-2026-3008.
On 2026-04-20, Moxa published advisory MPSA-258681 addressing CVE-2020-11868, an NTP-related vulnerability affecting several Ethernet switch product lines including PT-508, PT-510, PT-7528, PT-7728, PT-7828, PT-G503, and PT-G510 series. The advisory identified vulnerable firmware versions and provided remediation guidance via Moxa security advisory materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.