logo

CISA Alerts Users to Notepad++ Flaw Allowing Code Execution

ID: 46424a7a-5db6-5a02-88ed-6e234204038c

STIX ID: report--46424a7a-5db6-5a02-88ed-6e234204038c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

CISA added CVE-2025-15556—an integrity-check bypass in Notepad++'s WinGUp updater—to its Known Exploited Vulnerabilities catalog, warning that attackers could intercept or redirect update traffic to force installation of malicious installers and achieve arbitrary code execution; users and agencies are urged to apply vendor patches or discontinue use until mitigations are in place.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.