SB2026092466 - Multiple vulnerabilities in Notepad++
Published: September 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Improper Validation of Array Index (CVE-ID: N/A)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of an array index in the NPPM_SETCURRENTLANGTYPE handler when processing a negative LangType value. A local user can send a specially crafted NPPM message to cause a denial of service.
Direct NPPM message delivery is limited to same-integrity processes.
2) NULL pointer dereference (CVE-ID: N/A)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to NULL pointer dereference in the NPPM_GETCURRENTSCINTILLA and NPPM_GETCURRENTLANGTYPE handlers when processing a NULL output pointer. A local user can send a specially crafted NPPM message with a NULL output pointer to cause a denial of service.
Direct NPPM message delivery is limited to same-integrity processes.
3) NULL pointer dereference (CVE-ID: N/A)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of BufferID values in the NPPM_GETBUFFERLANGTYPE and NPPM_GETBUFFERENCODING handlers when processing a nonzero BufferID that does not identify a live buffer. A local user can send a specially crafted NPPM message with an invalid BufferID to cause a denial of service.
Direct NPPM message delivery is limited to same-integrity processes.
4) Buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper bounds checking in the NPPM_GETCURRENTWORD, NPPM_GETCURRENTLINESTR, and NPPM_GETFILENAMEATCURSOR handlers when processing a selection of 2048 or more characters. A local user can send window messages that select text and invoke a context menu command to cause a denial of service.
Exploitation requires the attacking process to run in the same session at the same or higher integrity level as Notepad++.
5) Out-of-bounds write (CVE-ID: N/A)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of an array index in FunctionParsersManager::getOverrideMapFromXmlTree when parsing an oversized langID attribute in Function List overrideMap.xml. A remote attacker can provide a crafted Function List configuration and induce the victim to open the Function List panel to cause a denial of service.
6) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose NetNTLMv2 challenge-response hashes.
The vulnerability exists due to improper UNC path validation in the isUncPath and isUncFileUrl helpers when processing crafted UNC paths or file URLs. A remote attacker can supply path or URL variations that Windows resolves to an attacker-controlled SMB share to disclose NetNTLMv2 challenge-response hashes.
User interaction is required to open a crafted session, project, or configuration file, or to activate a recognized link.
7) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify arbitrary files with elevated privileges.
The vulnerability exists due to missing authorization in the wWinMain UAC command-line operation dispatch when processing #UAC-SAVE# and related command-line arguments. A local user can invoke Notepad++ with crafted UAC operation arguments and approve the UAC prompt to modify arbitrary files with elevated privileges.
The UAC prompt does not display the destination path.
Remediation
Install update from vendor's website.
References
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-8wmf-7r8c-wf2w
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-3hx4-x297-6752
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9rr8-6vjg-gj52
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gr8w-74qx-pc2v
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-phqq-x4c2-7c2q