PT-2026-5735 · Notepad++ · Notepad++

Published

2025-12-09

·

Updated

2026-02-18

·

CVE-2025-15556

CVSS v4.0
7.7
VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.8.9
Description The WinGUp updater in Notepad++ versions prior to 8.8.9 has a flaw in how it verifies the integrity of updates. Specifically, downloaded update metadata and installers are not cryptographically verified. This allows an attacker who can intercept or redirect update traffic to cause the updater to download and execute an attacker-controlled installer, leading to arbitrary code execution with the privileges of the user. This issue is actively being exploited in attacks, and has been added to CISA’s Known Exploited Vulnerabilities catalog. Attackers may use man-in-the-middle (MitM) techniques or DNS spoofing to redirect users to malicious installers, potentially deploying ransomware, malware droppers, or establishing persistent backdoors.
Recommendations Update Notepad++ to version 8.8.9 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-15900
CVE-2025-15556

Affected Products

Notepad++