Use of Incorrectly-Resolved Name or Reference in Notepad++ - CVE-2026-77605

 

Use of Incorrectly-Resolved Name or Reference in Notepad++ - CVE-2026-77605

Published: August 24, 2026


Vulnerability identifier: #VU145001
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77605
CWE-ID: CWE-706
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to use of incorrectly-resolved name or reference in the \"Run by system\" feature when handling a user-selected .txt file that has a sibling .txt.cmd file in the same directory. A remote attacker can place a crafted sibling .txt.cmd file and trick the victim into triggering \"Run by system\" on the .txt file to execute arbitrary commands.

User interaction is required to trigger the vulnerable action.


Affected software

Notepad++

How to mitigate CVE-2026-77605

Install security update from vendor's website.

Notepad++ - update to 8.9.1

External References

Related Security Bulletins