Notepad++ released v8.9.6.1 to fix three vulnerabilities affecting versions up to 8.9.6, including two arbitrary code execution flaws tracked as CVE-2026-48778 and CVE-2026-48800, and a denial-of-service crash bug tracked as CVE-2026-48770. The most serious issue involves unsafe handling of the commandLineInterpreter value in config.xml, which can be passed to ShellExecute() when a user invokes the Open Containing Folder in cmd feature, allowing attacker-controlled programs to run instead of the intended interpreter. A separate flaw in shortcuts.xml also enables arbitrary code execution, while malformed XML structures can trigger application crashes.
Advisories and follow-on reporting said exploitation could occur if an attacker can tamper with %APPDATA%\Notepad++\config.xml, abuse the -settingsDir parameter through malicious .lnk files, poison cloud-synced settings, or socially engineer users into opening archives that place malicious configuration files in writable paths. A published proof of concept demonstrated the config.xml issue by launching calc.exe. The Canadian Centre for Cyber Security urged users and administrators to apply the update, while researchers recommended restricting write access to configuration directories, validating executable paths, and monitoring shared or synced settings locations in enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-01, public technical details and exploit code were disclosed for three Notepad++ flaws: CVE-2026-48800, CVE-2026-48778, and CVE-2026-48770. The disclosure included XML payloads and a PowerShell proof of concept, increasing exploitation risk for versions up to and including 8.9.6.
On 2026-05-28, the Canadian Centre for Cyber Security published advisory AV26-521 about the Notepad++ vulnerabilities. It urged users and administrators to review Notepad++'s release information and apply the necessary updates.
A GitHub security advisory published on 2026-05-26 documented GHSA-7hm3-wp5q-ccv9 / CVE-2026-48778, explaining that unsafe handling of the commandLineInterpreter value in config.xml could lead to arbitrary program execution. The advisory described attack vectors such as tampering with %APPDATA%\Notepad++\config.xml, abusing -settingsDir, cloud-sync poisoning, and social engineering, and included a proof of concept launching calc.exe.
On 2026-05-26, Notepad++ released version 8.9.6.1 and said it fixes three vulnerabilities affecting earlier versions. The patched issues were CVE-2026-48770, CVE-2026-48778, and CVE-2026-48800, including two arbitrary code execution flaws tied to config.xml and shortcuts.xml.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethecyberexpress.com
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcenotepad-plus-plus.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.