What is CVE-2026-54758?
CVE-2026-54758 is a vulnerability found in Notepad++ versions prior to 8.9.7. The flaw exists in the expandNppEnvironmentStrs function, where improper bounds checking can lead to a stack buffer overflow via crafted environment variables. Users are advised to update to version 8.9.7 or later immediately.
Azərbaycanca: CVE-2026-54758 Notepad++ proqramının 8.9.7-dən əvvəlki versiyalarında aşkarlanmış boşluqdur. expandNppEnvironmentStrs funksiyasında baş verən bu zəiflik, xüsusi hazırlanmış mühit dəyişənləri vasitəsilə stack buffer overflow-a səbəb ola bilər. İstifadəçilərə dərhal 8.9.7 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which software was CVE-2026-54758 discovered, and which function does it affect?
This vulnerability was discovered in Notepad++ versions prior to 8.9.7, affecting the expandNppEnvironmentStrs function.
What action is recommended to protect against CVE-2026-54758?
Users are advised to immediately update Notepad++ to version 8.9.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.