Skip to content
Notepad++ v8.9.7 Security Update Fixes 5 Vulnerabilities, Including Stack Buffer ...

Notepad++ v8.9.7 Security Update Fixes 5 Vulnerabilities, Including Stack Buffer ...

Gbhackers July 15, 2026

Notepad++ has released version 8.9.7, codenamed “Slava Ukraini.” This update addresses five security vulnerabilities related to session-file handling, environment-variable expansion, ZIP extraction, macro validation, and the Windows installation process.

The release date was July 14, 2026, and includes three CVE-tracked vulnerabilities as well as two additional GitHub Security Advisories that have not yet received CVE identifiers.

These vulnerabilities could expose users to various risks depending on how Notepad++ is used and whether attackers can provide malicious session files, archives, configuration files, or installer-related input. Users and organizations should update to version 8.9.7, especially in environments that handle untrusted files or shared Notepad++ configurations.

CVE-2026-54758 is a stack buffer overflow in the expandNppEnvironmentStrs function. This vulnerability occurs when input exceeds the space allocated to a stack-based memory buffer, potentially leading to application crashes, memory corruption, or even arbitrary code execution under certain conditions.

The practical impact depends on how easily an attacker can reach the vulnerable environment-string expansion process.

CVE-2026-57233 addresses the Zip Slip vulnerability, which is a weakness in archive extraction that allows a carefully crafted ZIP file to write files outside its intended destination directory. Attackers usually exploit such flaws by embedding traversal sequences, like “../”, in archive entry names.

If validation is inadequate, a malicious archive can overwrite files in other locations accessible to the current user, including application configuration paths or startup-related directories.

The update also resolves CVE-2026-52886, which involves bypassing validation of the backupFilePath setting in session.xml.

This vulnerability relates to starts_with path validation, which can be unsafe if a path appears to begin with an approved directory but resolves to a different location after normalization or traversal. An attacker may exploit a malicious session file to bypass intended path restrictions.

Notepad++ 8.9.7 further addresses a macro HMAC bypass affecting shortcuts.xml. HMAC validation should ensure the integrity of protected macro-related data, and bypassing this verification could allow tampered macro definitions to be accepted as legitimate.

Since macros can automate actions in the editor, maintaining the integrity of configuration files is crucial for users who or import Notepad++ settings.

The fifth issue concerns an install-time PowerShell command injection vulnerability. This can occur when installer-controlled or externally supplied data is passed to PowerShell without proper argument handling, escaping, or validation.

Successful exploitation could enable unintended PowerShell commands to run in the context of the user launching the installation, making it especially important to use verified installer downloads and timely patches.

In addition to the security patches, Notepad++ 8.9.7 introduces several usability improvements. The “Folder as Workspace” feature now remembers its expanded and collapsed state between sessions.

At the same time “Incremental ” now shows “nth/count” information to help users track the current match and the total number of matches. The release also includes other bug fixes and enhancements.

Users should download Notepad++ only from official project channels, update existing installations to version 8.9.7, and treat unsolicited archives, session files, shortcut configurations, and installers with caution.

The Notepad++ project has published a regression and critical bug reporting thread at [Notepad++ Community](

Gain browser-level visibility to expose decrypted phishing pages, speed investigations, and cut credential theft costs -> Power your SOC with ANY.RUN

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Cursor users on Windows may be at risk of arbitrary code execution following Mindgard's disclosure…

The China-linked Daxin backdoor has resurfaced in an active intrusion targeting a Taiwan-based subsidiary of…

A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational…

A newly documented malware framework dubbed OkoBot is targeting cryptocurrency users with a multi-stage intrusion…

Microsoft has temporarily halted delivery of the July 14, 2026, Windows 11 security update to…

Three Russian nationals and two St. Petersburg-based companies have been indicted in the United States…