← Back to search

CVE-2026-85279

8.6 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The flaw is a stack buffer overflow in Notepad++ due to improper handling of plugin-supplied lexers, allowing arbitrary code execution. This matters because it can lead to full compromise of the Notepad++ process context.
Exploitability
Exploitation is moderately hard requiring a malicious or compromised plugin that reports more than 30 lexers. Precondition is the user must have the affected version of Notepad++ installed.
Blast radius
If exploited, the impact is high as it can permit arbitrary code execution within the Notepad++ process context, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Notepad++ version 8.9.8 or later.
rcecode-executionbuffer-overflownotepad++

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexerCount() result controls a loop that writes to containers[30] without enforcing NB_MAX_EXTERNAL_LANG. A malicious or compromised plugin that reports more than 30 lexers can write beyond the stack array and corrupt control data, which can permit arbitrary code execution in the Notepad++ process context. This issue is fixed in version 8.9.8.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses

CWE-121

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.