CVE-2026-52886 is a path traversal vulnerability in Notepad++ session handling that was fixed in version 8.9.7. The flaw affects validation of the session.xml backupFilePath attribute, which was checked using a raw string prefix comparison based on starts_with semantics rather than canonicalized path validation. Because the path was not normalized before validation, traversal sequences could bypass the intended restriction and reference files outside the expected directory scope. When Notepad++ is subsequently launched in snapshot mode, the application may open the attacker-selected target file in an editor tab.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Notepad++ session handling flaw involving manipulated session.xml entries that can bypass path validation checks.
A path validation bypass vulnerability in Notepad++ session handling involving manipulated session.xml entries.
A path traversal vulnerability in Notepad++ session.xml handling that can cause the editor to load attacker-targeted files into tabs on next launch in snapshot mode, enabling read-only file theft such as SSH keys and .env files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.