notepad-plus-plus has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-85279High· 8.6Notepad++ is a free and open-source source code editor59CVE-2026-86054High· 7.8Notepad++ is a free and open-source source code editor43CVE-2026-77605High· 7.8Notepad++ is a free and open-source source code editor43CVE-2026-86056Medium· 5.5Notepad++ is a free and open-source source code editor42CVE-2026-85995High· 7.3Notepad++ is a free and open-source source code editor40
notepad-plus-plus vulnerabilities
CVEs affecting notepad-plus-plus, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-85279High· 8.6PoCNotepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplie…
CVE-2026-85288Medium· 6.7Notepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple Times entry point, calls macroPlayback() without …
CVE-2026-77605High· 7.8Notepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command …
CVE-2026-86054High· 7.8Notepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDi…
CVE-2026-86056Medium· 5.5PoCNotepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName…
CVE-2026-85995High· 7.3Notepad++ is a free and open-source source code editor
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its …