Notepad++ 8.9.6.2 released

The new version brings two security fixes and a follow-up patch.

Notepad++ has received two security updates: 8.9.6.1 closed multiple vulnerabilities allowing arbitrary code execution, then 8.9.6.2 followed on the same day to fix a bypass that left one of those patches incomplete.

What's new in 8.9.6.1

The update patches three CVEs:

CVE-2026-48778 — Arbitrary code execution was possible via a malicious config.xml file. An attacker who could place a crafted config file in the right location could use it to run code with the privileges of the logged-in user. CVE-2026-48778 — A second vector for the same vulnerability class, this time through a crafted shortcuts.xml file. CVE-2026-48770 — Notepad++ could be crashed by sending it malformed COPYDATASTRUCT data, a mechanism used for inter-process communication on Windows.

What's new in 8.9.6.2

After 8.9.6.1 shipped, it emerged that the fix for CVE-2026-48778 was not complete, a bypass scenario still existed that could allow the vulnerability to be re-triggered. The 8.9.6.2 release closes that remaining gap. Users who already updated to 8.9.6.1 should update again to 8.9.6.2.

This round of patches follows closely on 8.9.6, which was released the previous week and already included an initial fix for a security issue in the installer. The rapid follow-up cadence reflects how seriously the Notepad++ team is treating these vulnerabilities, the free, open-source text editor is one of the most widely installed Windows applications in the world, making it an attractive target.

How to download

Notepad++ on UpdateStar — version history and download links

Download Notepad++ on UpdateStar

Official downloads: notepad-plus-plus.org/downloads

about author