CVE-2026-34401 | Microsoft XmlNotepad prior 2.9.0.21 HTTP/SMB xml external entity reference (GHSA-5j32-486h-42ch)
A vulnerability was found in Microsoft XmlNotepad. It has been declared as problematic. Affected is an unknown function of the component HTTP/SMB. Such manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2026-34401. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.