Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting
May 5, 2026
Critical Qualcomm Chipset Flaws Enable Remote Code Execution
May 5, 2026
Critical Weaver E-cology RCE Actively Exploited Vulnerability Attacks
May 5, 2026
Home/CyberSecurity News/Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability
CyberSecurity News

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability

Notepad++ has released version 8.9.3. This latest update delivers critical security patches, introduces structural performance enhancements, and resolves persistent crash issues. This update...

Marcus Rodriguez
Marcus Rodriguez
March 31, 2026 2 Min Read
0 0

Notepad++ has released version 8.9.3. This latest update delivers critical security patches, introduces structural performance enhancements, and resolves persistent crash issues.

This update finalizes the text editor’s transition to a highly optimized XML parser, addressing multiple recent regressions while fortifying the application’s auto-update mechanism against documented vulnerabilities.

Notepad++ v8.9.3 Release

The most notable security implementation in version 8.9.3 is the remediation of a vulnerability within the application’s auto-updater framework.

The development team has updated the cURL component in WinGUp to version 8.19.0, mitigating a specific security issue, CVE-2025-14819.

Additionally, this release resolves an unintended privilege escalation bug introduced in prior versions. Previously, installing or removing a plugin caused Notepad++ to inadvertently relaunch with permanent administrative privileges. This regression has been successfully patched, ensuring the application adheres to standard user privilege limits during routine plugin management.

Vulnerability / Issue Component Affected Resolution
CVE-2025-14819 WinGUp Auto-Updater Updated embedded cURL to v8.19.0
Admin Privilege Bug Plugin Manager Prevented permanent admin rights upon N++ restart
MITM Update Failure Network / Updater Fixed plugin and update downloads behind corporate proxies

Core Upgrades and Crash Issues

To optimize the performance of reading and writing configuration files, Notepad++ has been steadily migrating from TinyXML to the newer pugixml parser over recent updates. Version 8.9.3 marks the completion of this structural overhaul.

Alongside the performance boost, developers have squashed several regressions stemming from this transition, including localized Workspace text errors and incorrect text displays for non-UTF8 documents.

The core components driving the text editor’s interface have also received substantial upgrades, with Scintilla updating to version 5.6.0 and Lexilla advancing to version 5.4.7.

System stability remains a primary focus in this deployment. The engineering team has successfully isolated and fixed a long-standing defect where initiating a print job caused the entire application to crash.

Similar fatal errors involving User Defined Languages (UDL) have been corrected. Furthermore, a memory leak occurring upon application exit has been sealed, preventing resource degradation during prolonged development sessions.

System administrators managing enterprise deployments gain valuable new controls in this release. The introduction of the disableNppAutoUpdate.xml file allows IT teams to explicitly disable auto-updates even when the WinGUp executable is present.

A secondary protective enhancement prevents XML configuration files from being inadvertently overwritten when updating portable packages via standard copy-and-paste methods.

Other notable fixes include resolving an issue where “Find in Files” failed to search file content on disk, stopping Notepad++ from spawning redundant Windows Explorer processes in Task Manager, and adding native Autocompletion and Function List support for the D programming language.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Axios NPM Packages Compromised in Supply Chain Attack

Next Post

Hackers Deploy RoadK1ll Malware to Pivot Pivoting Turn

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ScarCruft Supply Chain Attack Hits Gaming with Platform Windows
May 5, 2026
Silver Fox Deploys ValleyRAT & ABCDoor Via Fake Uses Notices
May 5, 2026
Cerberus Stalkerware Abuses Google Play for Leverages Accessibility
May 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us