CISA • 10w
Critical Arbitrary Code Execution Vulnerabilities in Notepad++
Notepad++ versions up to 8.9.6 are susceptible to high-severity arbitrary code execution (ACE) via CVE-2026-48800 and CVE-2026-48778 (CVSS 7.8). The vulnerabilities stem from a design flaw where the application implicitly trusts unvalidated XML configuration files stored in the user's %AppData% directory. Attackers can achieve ACE by injecting malicious commands into shortcuts.xml to manipulate the 'Run' menu or by hijacking the command-line interpreter path within config.xml. This vector enables reboot-surviving persistence that bypasses endpoint detection and response (EDR) tools focusing on the installation directory. Immediate remediation requires upgrading to version 8.9.6.1 or later.