Threats · 197 days ago

State-Linked Campaigns Hit Notepad++ and AI Ecosystems

Russia-linked APT28 weaponised CVE-2026-21509 against targets in Central and Eastern Europe. China-linked Lotus Blossom compromised the Notepad++ supply chain.

CVE-2026-21509

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a… EPSS 73% (99th percentile).

CISA federal remediation date Feb 16 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-03

Editions

Related stories