Critical DoS Vulnerability in Notepad++ Exposes Users to Attacks

Critical DoS Vulnerability in Notepad++ Exposes Users to Attacks

First seen 8 Jun 2026, 19:52 UTC Securinattack.mitre.orgnvd.nist.gov 91% similarity 57.8

Article Content

Browse articles
ThreatCluster

A stack-based buffer overflow vulnerability (CVE-2026-5525) has been identified in Notepad++ version 8.9.3. This flaw occurs when a user drops a directory path of 259 characters onto the application, causing a stack buffer overflow and resulting in a denial of service (DoS). The vulnerability was reproduced in a sandboxed environment and requires only LAN or WiFi adjacency to exploit. The issue arises from inadequate bounds checking when appending a backslash and null terminator to the buffer. The vulnerability was remediated by implementing proper bounds validation. Users are advised to update to the latest version to mitigate risks. This incident highlights the potential for exploitation in widely-used applications, affecting numerous users globally.

Key Points: • CVE-2026-5525 is a critical stack-based buffer overflow in Notepad++ 8.9.3. • Exploitation leads to denial of service, requiring only local network access. • Users should update to the latest version to mitigate the vulnerability.

ThreatCluster AI

Timeline

2026-04-10
CVE-2026-5525 published
A stack-based buffer overflow vulnerability in Notepad++ was disclosed, affecting version 8.9.3.
Securin
2026-06-08
Vulnerability details reported
The vulnerability can be triggered by dragging a specific directory path, leading to application crash.
nvd.nist.gov
2026-06-08
Remediation released
Notepad++ developers released a fix that adds proper bounds checking to prevent the overflow.
Securin

Community

Browse all →