Skip to content
Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

Critical Vulnerability in Notepad++ Allows DoS and Memory Disclosure

First seen 27 Apr 2026, 16:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 28, 2026 at 16:06 UTC
  • CVE-2026-3008 allows attackers to crash Notepad++ or leak memory data.
  • Users must upgrade to Notepad++ version 8.9.4 to mitigate the vulnerability.
  • The vulnerability was disclosed on April 27, 2026, with a PoC available since April 20.

A format string injection vulnerability, tracked as CVE-2026-3008, has been identified in Notepad++ version 8.9.3. This flaw enables attackers to crash the application or leak sensitive memory information through a malicious language pack. The vulnerability affects users of Notepad++ who load the compromised nativeLang.xml file, leading to a denial of service (DoS) and potential information disclosure. The Cybersecurity Agency of Singapore (CSA) has issued an urgent advisory for users to upgrade to version 8.9.4 to mitigate the risk. The vulnerability was publicly disclosed on April 27, 2026, with a proof of concept available since April 20, 2026. Users are strongly advised to update their software immediately to avoid exploitation. The attack vector relies on the improper handling of format strings in the application, which can lead to crashes and memory leaks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 136d ago How this analysis works

Timeline

2026-04-20
First public PoC for CVE-2026-3008 released
2026-04-27
CVE-2026-3008 published
2026-04-27
CSA issues advisory for Notepad++ users to update
2026-04-28
Articles report on the vulnerability and its implications

More articles in this cluster (6)

Following this threat?

Track CVE-2026-3008 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed