CVE-2026-48800

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48800 is an OS Command Injection vulnerability found in Notepad++, a popular text editor for Windows. This flaw specifically affects the `UserDefinedCommands` component within the `shortcuts.xml` file. The vulnerability arises from insufficient input validation of the `<Command>` tag, which is subsequently passed directly to the `ShellExecute` function as an executable path. Exploitation of CVE-2026-48800 could allow an attacker with local access to execute arbitrary code on the affected system. This vulnerability was addressed by the Notepad++ development team in version 8.9.6.1, released on May 26, 2026, as part of a patch for a trio of security issues.

Description
-

Social media

Hype score
Not currently trending
  1. Se han revelado vulnerabilidades críticas (CVE-2026-48778 y CVE-2026-48800) en el popular editor Notepad++ que permiten la ejecución arbitraria de código (RCE). El fallo radica en la falta de validación de comandos dentro de los archivos de configuración (config.xml y https:

    @tpx_Security

    29 May 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Notepad++ &lt;= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800) poc: https://t.co/hynIeZp5SS https://t.co/Et7ZKIEN5v

    @hackingspace

    29 May 2026

    272 Impressions

    0 Retweets

    3 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. csirt_it: ‼️ #Notepad++: disponibili #PoC per le CVE-2026-48800, CVE-2026-48778 e CVE-2026-48770 che interessano il noto editor di testo Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Denial of Service 🔗 https://t.co/tG5AKVnGtJ 🔄 Aggiorname… https://

    @Vulcanux_

    28 May 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 اذا انت من الجيل القديم ولاتزال تستخدم Notepad++ حدّث البرنامج فوراً إلى الإصدار الأخير (v8.9.6.1). 📍 الثغرة الأولى: (CVE-2026-48770) 📍 الثغرة الثانية: (CVE-2026-48778) 📍

    @buhaimedi

    28 May 2026

    3715 Impressions

    4 Retweets

    35 Likes

    18 Bookmarks

    3 Replies

    0 Quotes

  5. ‼️ #Notepad++: disponibili #PoC per le CVE-2026-48800, CVE-2026-48778 e CVE-2026-48770 che interessano il noto editor di testo Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Denial of Service 🔗 https://t.co/DEGdsIPlJS 🔄 Aggiornamenti disponibili 🔄 h

    @csirt_it

    28 May 2026

    253 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. برای ابزار پرکاربرد Notepad plus plus چندین آسیب پذیری از نوع Code execution با کدهای شناسایی CVE-2026-48770 و CVE-2026-48778 و CVE-2026-48800 منتشر شده است . برای امن سازی به نسخه 8.9.6.1 به رو

    @EthicalSafe

    28 May 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.