OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86054

HIGH · CVSS 7.8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Notepad++ versions prior to 8.9.8 are vulnerable to a stack buffer overflow in the session saving functionality, which can lead to a denial of service when an excessively long settings directory path is used. This vulnerability arises from unbounded string copying and concatenation, potentially allowing for exploitation in environments where Notepad++ is deployed. Organizations using Notepad++ should prioritize upgrading to version 8.9.8 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86054
Severity
HIGH
CVSS
7.8
EPSS
0.23%

Original NVD Description

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDir= into backupPathName[MAX_PATH] with unbounded wcscpy and appends SESSION_BACKUP_EXT with unbounded wcscat. A sufficiently long settings directory causes the backup suffix to exceed the fixed stack buffer when Notepad++ saves the session, and the protected release build terminates through its stack canary, causing denial of service. This issue is fixed in version 8.9.8.