logo

CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks

ID: 4740a513-e4d0-5fd7-bfc3-a6bec957c912

STIX ID: report--4740a513-e4d0-5fd7-bfc3-a6bec957c912

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CVE-2025-15556 is a critical Notepad++ WinGUp updater flaw that fails to verify integrity of downloaded update packages, enabling attackers who can intercept or redirect update traffic to install and execute arbitrary code on Windows endpoints; CISA added the issue to its Known Exploited Vulnerabilities catalog, vendors released a patch (Notepad++ 8.8.9+), and organizations are urged to patch, disable WinGUp, scan for outdated installs, and apply network mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.