PT-2026-96850 · Notepad++ · Notepad++

CVE-2026-85288

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.8
Description Notepad++ incompletely enforces HMAC (Hash-based Message Authentication Code) validation for the shortcuts.xml file. The issue occurs because the WM MACRODLGRUNMACRO entry point, used for running a macro multiple times, calls the macroPlayback() function without the validation typically applied by the command() function. This allows a tampered shortcuts.xml macro, which would otherwise be blocked via the Macro menu or a shortcut key, to execute through the multi-run dialog. Consequently, an attacker could invoke internal commands, including those that launch external programs, within the context of the current user.
Recommendations Update to version 8.9.8.

Exploit

Fix

Protection Mechanism Failure

Insufficient Verification of Data Authenticity

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85288
GHSA-759J-G8J4-867P

Affected Products

Notepad++