CVE-2026-2538

Severity CVSS v4.0:
HIGH
Type:
CWE-426 Untrusted Search Path
Publication date:
16/02/2026
Last modified:
18/02/2026

Description

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolled search path. Attacking locally is a requirement. The attack's complexity is rated as high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.