Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

First seen 27 Apr 2026, 16:29 UTC Csa.Sgllgsjsm.github.ioCybersecuritynewsGbhackersThecyberexpress+1 89% similarity 75.2

Article Content

Browse articles
ThreatCluster

A format string injection vulnerability, tracked as CVE-2026-3008, has been identified in Notepad++ version 8.9.3. This flaw enables attackers to crash the application or leak sensitive memory information through a malicious language pack. The vulnerability affects users of Notepad++ who load the compromised nativeLang.xml file, leading to a denial of service (DoS) and potential information disclosure. The Cybersecurity Agency of Singapore (CSA) has issued an urgent advisory for users to upgrade to version 8.9.4 to mitigate the risk. The vulnerability was publicly disclosed on April 27, 2026, with a proof of concept available since April 20, 2026. Users are strongly advised to update their software immediately to avoid exploitation. The attack vector relies on the improper handling of format strings in the application, which can lead to crashes and memory leaks.

Key Points: • CVE-2026-3008 allows attackers to crash Notepad++ or leak memory data. • Users must upgrade to Notepad++ version 8.9.4 to mitigate the vulnerability. • The vulnerability was disclosed on April 27, 2026, with a PoC available since April 20.

ThreatCluster AI How this analysis works

Timeline

2026-04-20
First public PoC for CVE-2026-3008 released
2026-04-27
CVE-2026-3008 published
2026-04-27
CSA issues advisory for Notepad++ users to update
2026-04-28
Articles report on the vulnerability and its implications

Community

Browse all →

Tracked Entities in This Story