CVE-2026-54758 – Notepad++

CVSS 7.8 IMPORTANT Zero Day – Immediate Deployment

“Malicious input can cross trusted boundaries and turn routine Notepad++ activity into code execution.”

Notepad++ 8.9.7 fixes two High-severity vulnerabilities. CVE-2026-57233 allows a malicious ZIP entry processed by WinGup to escape its intended plugin directory, overwrite another plugin DLL, and execute attacker-controlled code when that plugin loads. CVE-2026-57233 has a CVSS score of 8.1, High severity.

CVE-2026-54758 is a stack buffer overflow in environment-variable expansion that can corrupt memory, crash Notepad++, and potentially execute code. CVE-2026-54758 has a CVSS score of 7.8, High severity. Public proof-of-concept material is available for both vulnerabilities.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.