| |
Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)
Notepad++ v8.9.6.1 contains a critical remote code execution vulnerability (CVE-2026-52884) that allows arbitrary code execution through path traversal in the shortcuts.xml configuration file. The vulnerability bypasses the CVE-2026-48800 security patch by using "..\..\" directory traversal sequences (e.g., C:\Windows\System32\..\..\Users\Downloads\malware.exe) that pass the trusted directory validation check because the path is not canonicalized before verification. An attacker with local user access can modify shortcuts.xml to execute malicious executables or abuse trusted system executables like cmd.exe and powershell.exe without triggering security warnings.
Read Full Article →
← More Tech news