OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77605

HIGH · CVSS 7.8 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Notepad++ versions prior to 8.9.8 on Windows are vulnerable to a flaw that allows an attacker to execute a malicious sibling script by manipulating the "Run by system" action. This can lead to unauthorized command execution under the current user's privileges, posing a significant security risk. Organizations using Notepad++ for development should prioritize updating to version 8.9.8 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77605
Severity
HIGH
CVSS
7.8
EPSS
0.21%
Windows

Original NVD Description

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file. This issue is fixed in version 8.9.8.