CVE-2026-86056Medium· 5.5▾ TwilightPoC availableNotepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.3 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members without checking for null. A process running at the same or a higher Windows integrity level on the same desktop can send NPPM_SAVESESSION with a null lParam, immediately terminating Notepad++ and causing denial of service and loss of unsaved documents. This issue is fixed in version 8.9.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85279High· 8.6Notepad++ is a free and open-source source code editor
CVE-2026-77605High· 7.8Notepad++ is a free and open-source source code editor
CVE-2026-85288Medium· 6.7Notepad++ is a free and open-source source code editor
CVE-2026-86054High· 7.8Notepad++ is a free and open-source source code editor
CVE-2026-85995High· 7.3Notepad++ is a free and open-source source code editor
CVE-2026-48521Medium· 5.9Envoy is an open source edge and service proxy designed for cloud-native applications