CVE-2026-3008: Notepad++
Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
Affected products
- Notepad++ Notepad++: version 8.9.3 only
Published 2026-04-27. Last modified 2026-06-17.