CSA has issued a CVE ID to a vulnerability reported in Notepad++ as part of CSA's Responsibility Vulnerability Disclosure Policy. Users and administrators of the affected product version are advised to update to the latest version 8.9.4 immediately.
CSA has issued a CVE ID (CVE-2026-3008) to a vulnerability reported in Notepad++, an open-source text editor. The Product Owner of Notepad++ has released a security update to address the vulnerability.
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
The vulnerability affects Notepad++ version 8.9.3.
Users and administrators of the affected product version are advised to update to the latest version 8.9.4 immediately.
• Informer: Mr Hazley Samsudin • Product Owner: Notepad++
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
