Skip to content
COOEY

EXPOSURES › CVE-2025-15556

CVE-2025-15556

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-02-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-15556 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Notepad++'s WinGUp updater lacks integrity checks, enabling attackers to execute arbitrary code via compromised updates.

Notepad++'s update mechanism via WinGUp is vulnerable to intercepting update traffic, allowing attackers to execute arbitrary code with the privileges of the user. This could lead to a severe security breach.

Shame score — Vulnerability actively exploited, posing a high risk to users' systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.