Exploited Vulnerabilities Daily
🌐 English

Home › Notepad++

CVE-2025-15556: Notepad++ Notepad++

EPSS1.7%No. 1604 of 1739 in KEV
CVE year2025~1 yrs before listing
Same vendor in KEV1
Same product1
FieldValue
VendorNotepad++
ProductNotepad++
NameNotepad++ Download of Code Without Integrity Check Vulnerability
Added to KEV2026-02-12
US federal due date2026-03-05
Ransomware useUnknown
CWECWE-494

CISA description

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.

NVD — CVE-2025-15556

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Notepad++ Notepad++ vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-12.