PT-2026-90780 · Notepad++ · Notepad++

CVE-2026-85279

·

Published

2026-09-12

·

Updated

2026-09-22

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.8
Description A stack buffer overflow exists in the plugin loading mechanism within the PluginsManager::loadPluginFromPath function. The issue occurs because the result of the GetLexerCount() function, provided by a plugin, controls a loop that writes to containers[30] without enforcing the NB MAX EXTERNAL LANG limit. A malicious or compromised plugin reporting more than 30 lexers can write beyond the stack array and corrupt control data, potentially allowing arbitrary code execution within the process context.
Recommendations Update to version 8.9.8.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85279
GHSA-H2WQ-6X75-H8Q2

Affected Products

Notepad++