CVE detail
CVE-2025-15556
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
Disclosed at the end of January, the SolarWinds vulnerability was likely exploited as a zero-day since December 2025.
newswww.securityweek.comFeb 13, 2026, 10:36 AMU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws […]
newssecurityaffairs.comFeb 13, 2026, 8:27 AMNo excerpt available.
Mitigationwww.cisa.govFeb 3, 2026, 1:15 AM- https://notepad-plus-plus.org//news//clarification-security-incident/notepad-plus-plus.org
No excerpt available.
Vendor Advisorynotepad-plus-plus.orgFeb 3, 2026, 1:15 AM - https://www.vulncheck.com/advisories/notepad-plus-plus-wingup-updater-lacks-update-integrity-verificationwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comFeb 3, 2026, 1:15 AM - https://notepad-plus-plus.org/news/hijacked-incident-info-update/notepad-plus-plus.org
No excerpt available.
Vendor Advisorynotepad-plus-plus.orgFeb 3, 2026, 1:15 AM - https://github.com/notepad-plus-plus/wingup/commit/ce0037549995ed0396cc363544d14b3425614fdbgithub.com
No excerpt available.
Exploitgithub.comFeb 3, 2026, 1:15 AM No excerpt available.
Exploitgithub.comFeb 3, 2026, 1:15 AM- https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fixcommunity.notepad-plus-plus.org
No excerpt available.
Release Notescommunity.notepad-plus-plus.orgFeb 3, 2026, 1:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66398CVSS 9.4 · Critical
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD…
- CVE-2026-50562CVSS 9.3 · Critical
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/w…
- CVE-2021-47987CVSS 7.7 · High
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork o…
- CVE-2021-47986CVSS 7.7 · High
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attacker…
- CVE-2026-55698CVSS 8.8 · High
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct…
- CVE-2026-55697CVSS 7.5 · High
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository…