A vulnerability described as critical has been identified in Notepad++ up to 8.9.3. The affected element is an unknown function of the component File Drop Handler. The manipulation results in stack-based buffer overflow.

This vulnerability is reported as CVE-2026-5525. The attack requires a local approach. No exploit exists.

Upgrading the affected component is recommended.