Actively exploited vulnerability
Notepad++: code execution flaw under attack
CVE-2025-15556 · Notepad++ Download of Code Without Integrity Check Vulnerability
What is affected
Notepad++ is mostly run by companies, schools and public bodies, not on home computers. You are unlikely to have it yourself, but organisations that hold your data may. Breaches that start with flaws like this one are how personal data ends up leaked.
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
What an attacker can do
This is a code execution flaw. It lets an attacker run their own commands or programs on the affected system. In practice that usually means taking it over: installing malware, stealing data or using it to reach other devices on the same network.
- How it is reached
- Over the internet or network
- Access the attacker needs
- No account needed
- Does the victim have to do something?
- Yes, ordinary use is enough
What to do
- At home: nothing to install. Keep your own devices updated and use a different password for every service, so that a breach at one organisation does not open your other accounts.
- If you administer Notepad++ at work: apply the vendor's fix or mitigation now and review logs for signs of compromise, because the flaw was being exploited before it was listed.
- If the product is past its support date and no fix exists, take it off the internet or retire it.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vendor advisories and fixes
- notepad-plus-plus.orgnotepad-plus-plus.org/news/clarification-security-incident/
- community.notepad-plus-plus.orgcommunity.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix
How urgent is it
CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue on February 12, 2026, which means there is reliable evidence of attacks in the wild. US federal agencies must fix it by March 5, 2026, a deadline that has already passed. That deadline does not bind anyone else, but it shows how seriously the agency rates it.
The EPSS model estimates a 1.8% probability that this flaw will be exploited somewhere in the next 30 days. That is higher than 77% of all scored vulnerabilities.
Its CVSS severity score is 7.7 out of 10 (high), as recorded in the US National Vulnerability Database.
Technical description
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.