Notepad++ released version 8.9.7 with fixes for five security vulnerabilities, including a critical installer-based flaw that could allow PowerShell command injection and arbitrary code execution. Reported issues also include a stack buffer overflow, a Zip Slip path traversal vulnerability in the WinGUp updater, a session.xml path validation bypass, and a shortcuts.xml macro HMAC integrity bypass. The weaknesses could be exploited through tampered installers, malicious local configuration files, or abuse of update extraction to overwrite files, corrupt memory, bypass protections, or fully compromise a system.
The Canadian Centre for Cyber Security issued advisory AV26-703, warning that vulnerabilities affect Notepad++ versions prior to 9.7 and urging users and administrators to review the vendor guidance and apply updates. The notice points to the Notepad++ security advisory and release resources for remediation, while reporting indicates users should update manually rather than wait for the staged auto-updater rollout.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Notepad++ version 8.9.7 was released with patches for five vulnerabilities, including a critical installer-based PowerShell command injection flaw. The release also fixed a stack buffer overflow, a Zip Slip issue in the WinGUp updater, a session.xml path validation bypass, and a shortcuts.xml macro HMAC integrity bypass.
On July 14, 2026, Notepad++ published a security advisory addressing vulnerabilities affecting versions prior to 9.7. The advisory was later highlighted by the Canadian Centre for Cyber Security, which urged users and administrators to apply the necessary updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecommunity.notepad-plus-plus.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.