Security
Loading…

CVE-2025-15556

UNKNOWNKnown Exploited
Description

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.

Timeline
Published:February 12th, 2026 12:00 AM
Last modified:February 12th, 2026 12:00 AM
Added to KEV:February 12th, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Notepad++

Products

Notepad++
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute