CVE-2025-15556

Confirmed PUBLISHED

Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification

notepad-plus-plus · notepad-plus-plus

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.7 High EPSS 1.3%

At a Glance

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.

cisa
CVE Published
Feb 03, 2026
Exploitation Reported
Jun 01, 2026
CVSS
7.7 High
EPSS
1.3%
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
notepad-plus-plus
notepad-plus-plus

0 to < 8.8.9

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.