What is CVE-2026-71858?
CVE-2026-71858 affects Notepad++ versions prior to 8.9.7, where macros from an attacker-controlled `shortcuts.xml` bypass HMAC validation for UserDefinedCommands. This allows invoking Scintilla actions and the internal "Open in Default Viewer" command in an elevated Notepad++ process. Users should immediately upgrade to version 8.9.7 or later.
Azərbaycanca: CVE-2026-71858 Notepad++ proqramının 8.9.7 versiyasından əvvəlki versiyalarına təsir edən boşluqdur. Bu, təcavüzkar tərəfindən idarə olunan `shortcuts.xml` faylındakı makroların HMAC doğrulamasını keçərək yüksək imtiyazlı Notepad++ prosesində Scintilla əməliyyatları və "Default Viewer-də Aç" funksiyasını işə salmasına imkan verir. İstifadəçilər dərhal 8.9.7 və ya daha yuxarı versiyaya yeniləməlidirlər.
FAQ2
Which versions of Notepad++ are affected by CVE-2026-71858?
This vulnerability affects versions of Notepad++ prior to 8.9.7.
What can an attacker do by exploiting CVE-2026-71858 in Notepad++?
By exploiting macros in a `shortcuts.xml` file to bypass HMAC validation, an attacker can invoke Scintilla actions and the 'Open in Default Viewer' command in an elevated Notepad++ process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.