SB20260824293 - Use of Incorrectly-Resolved Name or Reference in Notepad++
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-77605)
CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to use of incorrectly-resolved name or reference in the \"Run by system\" feature when handling a user-selected .txt file that has a sibling .txt.cmd file in the same directory. A remote attacker can place a crafted sibling .txt.cmd file and trick the victim into triggering \"Run by system\" on the .txt file to execute arbitrary commands.
User interaction is required to trigger the vulnerable action.
Remediation
Install update from vendor's website.