CVE-2025-15556

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.

Scoring

Severity
HIGH
CVSS base score
7.7
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
1.71%
CISA KEV
Known exploited vulnerability
CWE
CWE-494
Published
2026-02-03
Last modified
2026-03-05

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs