CVE-2025-15556Active Exploitation(notepad-plus-plus / notepad\+\+)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch notepad-plus-plus notepad\+\+ systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-494

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad\+\+

Threat summary

  • Active exploitation appears in 23 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 35 mentions across 14 observed days

What's happening

  • Active exploitation reported across 23 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 25 signals
  • Disclosure: 6 classified signals
  • General: 5 classified signals
  • Peaked 8d ago at 14 mentions (2026-02-13); latest day: 1
  • 35 total mentions across 14 days

Affected systems

Products
notepad\+\+

Deep dive

Activity timeline35 mentions / 14d
0471114Mentions · 2026-02-03: 3Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-07: 3Mentions · 2026-02-12: 4Mentions · 2026-02-13: 14Mentions · 2026-02-14: 2Mentions · 2026-02-15: 1Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Mentions · 2026-02-26: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-02-13: 1Exploit Tool / Code · 2026-02-26: 1Active Exploitation · 2026-02-12: 4Active Exploitation · 2026-02-13: 12Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-15: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-13: 10Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-05: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 12Technical Details · 2026-02-14: 2Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-26: 102-0302-0402-0502-0702-1202-1302-1402-1502-1602-1702-1802-2002-2604-22
Signal classification4 categories
Active Exploitation
2262.9%
Disclosure
617.1%
General
514.3%
Patch
25.7%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-033
Disclosure2General1
2026-02-041
Disclosure1
2026-02-051
Patch1
2026-02-073
Disclosure2General1
2026-02-124
Active Exploitation4
2026-02-1314
Active Exploitation11Disclosure1General1Patch1
2026-02-142
Active Exploitation2
2026-02-151
Active Exploitation1
2026-02-161
Active Exploitation1
2026-02-171
Active Exploitation1
2026-02-181
Active Exploitation1
2026-02-201
General1
2026-02-261
Active Exploitation1
2026-04-221
General1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks Source: https://cybersecuritynews.com/notepad-code-execution-vulnerability/ CISA has added CVE-2025-15556 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation of a critical code execution flaw in Notepad++, a widely used open-source text editor popular among developers and IT professionals. Attackers can intercept or redirect update traffic, tricking users into installing malicious payloads that execute arbitrary code with user-level privileges. Threat actors could leverage man-in-the-middle (MitM) techniques on unsecured networks to serve tampered installers, potentially deploying ransomware, malware droppers, or persistent backdoors. #cybersecuritynews #vulnerability

    Post summary

    CISA reports that CVE‑2025‑15556 is actively exploited in the wild through update‑traffic manipulation, enabling code execution on Notepad++ users.

    2412122266.5K
    48.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CISA has added 3 vulnerabilities to the KEV Catalog CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability: Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user. CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability: Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability: Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

    Post summary

    CISA has added three CVEs to its Known Exploited Vulnerabilities catalog, confirming they are being exploited, with brief technical details but no PoC or patch information.

    02411183715.8K
    164.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft vulnerability CVE-2024-43468, Notepad++ vulnerability CVE-2025-15556, SolarWinds vulnerability CVE 2025-40536, & Apple vulnerability CVE-2026-20700 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://go.dhs.gov/Z3Q https://t.co/0hbYVOzt7p

    Post summary

    The tweet announces that four CVEs have been added to the DHS KEV catalog, indicating they are currently being exploited and urging organizations to apply mitigations.

    53838598.5K
    291.8K followersView on X
  • LordSudo@L0rd5ud0
    General

    New post: CVE-2025-15556 : the Notepad++ supply chain attack. They never touched the code. Just the updater. Full breakdown + IOCs + detection guide http://blog.lordsudo.com/posts/supplychainnotepad #CyberSecurity #ThreatIntel #BlueTeam #SupplyChain https://t.co/JWRAKivDnh

    Post summary

    The post announces a supply chain vulnerability (CVE‑2025‑15556) affecting Notepad++’s updater, but provides no PoC, exploit code, active exploitation evidence, patch, or technical details.

    2902531.2K
    696 followersView on X
  • Casey Muratori@cmuratori
    General

    @lindaoneesama I meant you must be new here if you're accusing me of not having read the CVE materials before commenting. But to answer your question, for Notepad++ I was talking about CVE-2025-15556.

    Post summary

    The tweet simply references CVE‑2025‑15556 for Notepad++ without providing any PoC, exploit code, evidence of active exploitation, patch info, or technical details.

    100160664
    67.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/12追加) 🛡️No.1515 CVE-2024-43468 Microsoft Configuration Manager SQL Injection Vulnerability ============= CVSSスコア: 9.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:SQLインジェクション (CWE-89 / Microsoft Corporation) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたリクエストを受信することで、サーバーや基盤となるデータベース上でコマンドを実行される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 🛡️No.1516 CVE-2025-15556 Notepad++ Download of Code Without Integrity Check Vulnerability ============= CVSSスコア: 7.7 (Base) / VulnCheck CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:ダウンロードしたコードの完全性検証不備 (CWE-494 / VulnCheck) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、アップデートトラフィックを傍受またはリダイレクトして、攻撃者が制御するインストーラをダウンロード・実行される恐れがあります。この脆弱性を悪用することで、ユーザー権限で任意のコードが実行される可能性があります。 https://notepad-plus-plus.org/news/clarification-security-incident/ https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix 🛡️No.1517 CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability ============= CVSSスコア: 8.1 (Base) / SolarWinds CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / SolarWinds) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから制限された特定機能にアクセスされる恐れがあります。 https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 🛡️No.1518 CVE-2026-20700 Apple Multiple Buffer Overflow Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:バッファエラー (CWE-119 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: メモリへの書き込み権限を持つ攻撃者により、ローカル上で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/126346 https://support.apple.com/en-us/126348 https://support.apple.com/en-us/126351 https://support.apple.com/en-us/126352 https://support.apple.com/en-us/126353 CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added four known exploited vulnerabilities—CVE‑2024‑43468, CVE‑2025‑15556, CVE‑2025‑40536, and CVE‑2026‑20700—to its KEV catalog, providing vendor patch references and technical details for each.

    000803.7K
    42.5K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    The message announces that four high‑severity CVEs have been added to the KEV list, indicating active exploitation, and urges rapid patching.

    020201.8K
    119.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2022-1743 2 - CVE-2026-20841 3 - CVE-2025-15556 4 - CVE-2026-25253 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists the top five trending CVEs with a link to CVEShield, but does not provide technical details, exploits, or mitigation information.

    01020197
    1.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Notepad++ update integrity verification flaw CVE-2025-15556 allows attackers to push malicious updates and gain arbitrary code execution #RCE. Fixed in 8.8.9 and later. #Patch #Patch #Patch

    Post summary

    The post alerts that CVE-2025-15556 in Notepad++ allows malicious update delivery leading to arbitrary code execution, and that the issue is fixed in version 8.8.9 and later.

    02010283
    7.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    🚨 ثغرة Notepad++ مستغلة حالياً CISA أضافت CVE-2025-15556 لقائمة الثغرات المعروفة والمستغلة. هذه الثغرة تسمح بتنفيذ أوامر برمجية عن بعد في Notepad++. لاحظنا نشاط استغلال لهذه الثغرة. 💡 إجراءات الحماية: - حدث Notepad++ فوراً لآخر إصدار. - كن حذراً من فتح ملفات مجهولة المصدر. 🔗 https://cybersecuritynews.com/notepad-code-execution-vulnerability/ #الأمن_السيبراني #CVE_2025_15556 #Notepad

    Post summary

    CISA lists CVE-2025-15556 as an actively exploited vulnerability in Notepad++, allowing remote command execution, and urges users to update immediately.

    0002045
    51 followersView on X
  • Grok@grok
    Disclosure

    Notepad++ is a third-party app, not a Microsoft product—CVE-2025-15556 affected its updater, leading to a supply chain attack. Windows Recall did spark privacy concerns, prompting Microsoft to make it opt-in and add safeguards. All OSes have security risks; Windows' popularity makes it a bigger target. Linux excels in servers for good reason!

    Post summary

    The text reports that CVE‑2025‑15556 affected the Notepad++ updater, but provides no technical specifics, exploitation evidence, or mitigation information.

    2000091
    8.1M followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Notepad++ Supply-Chain Shock: CVE-2025-15556 Let Attackers Trojanize Updates via WinGUP Flashpoint details how CVE-2025-15556 in Notepad++’s WinGUP updater failed to verify installer signatures, enabling MitM/DNS poisoning to redirect update traffic and deliver trojanized “update.exe” payloads tied to the China-linked “Lotus Blossom” campaign (including Cobalt Strike and the Chrysalis backdoor). Patch/upgrade (v8.9.1+), hunt for the described TTPs/persistence artifacts, and monitor for malicious update infrastructure to reduce supply-chain exposure. 🕷️ Malware: Cobalt Strike, Chrysalis (backdoor) 🎯 Target: Global/Government & Telecom #️⃣ Category: #Vulnerability #APT #CyberIntel #BlueTeam 🔗 URL: https://flashpoint.io/blog/what-to-know-about-the-notepad-supply-chain-attack/

    Post summary

    Flashpoint reports that CVE-2025-15556 in Notepad++’s WinGUP updater allows attackers to perform MitM/DNS poisoning and deliver trojanized updates, with evidence of active exploitation via the Lotus Blossom campaign, and recommends upgrading to v8.9.1+.

    0001054
    220 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    The tweet announces four CVEs added to the KEV as exploited bugs and urges quick patching, indicating they are actively exploited in the wild.

    00010421
    119.3K followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    CISA warns of active exploitation of Notepad++ vulnerability CVE-2025-15556. Users urged to update to version 8.8.9 or later immediately. Link: https://thedailytechfeed.com/notepad-vulnerability-cve-2025-15556-actively-exploited-users-urged-to-patch-immediately/ #Security #Vulnerability #Exploit #Update #Notepad #Patch #CISA #Software #Alert #CVE #Bug #Threat #Protection #Technology #Safety #Cyber #IT #Digital #Risk #Awareness

    Post summary

    CISA reports that CVE‑2025‑15556 in Notepad++ is actively exploited in the wild, and users are advised to patch immediately by updating to version 8.8.9 or newer.

    0001048
    233 followersView on X
  • GuardingPearSoftware@GuardingPearSof
    Patch

    CISA has added a critical code execution flaw in Notepad++ to its Known Exploited Vulnerabilities (KEV) catalog. Notepad++ is a widely used open-source text editor popular among developers and IT teams. The vulnerability (CVE-2025-15556) allows attackers to intercept or manipulate update traffic, tricking users into installing malicious payloads. The issue has been fixed in version 8.8.9 and all later releases.

    Post summary

    CISA flagged CVE-2025-15556 as a critical code execution flaw in Notepad++; the issue has been patched in version 8.8.9 and later, and the vulnerability involves manipulation of update traffic to deliver malicious payloads.

    0000171
    208 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    🔍 **CVE-2025-15556** is a vulnerability in Notepad++ enabling download of code without integrity checks, listed among four critical CVEs added to CISA's Known Exploited Vulnerabilities (KEV) catalog. No specific mitigation details are available, but patching Notepad++ is recommended as a standard response for such flaws. #NotepadPlusPlus #KEV

    Post summary

    CVE-2025-15556 is a Notepad++ flaw that allows downloading code without integrity checks and is listed in CISA’s KEV catalog, indicating it is actively exploited. Patching the application is recommended as the primary mitigation.

    1000044
    315 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2024-43468 Microsoft Configuration Manager の SQL インジェクション脆弱性 CVE-2025-15556 Notepad++ における整合性チェックなしのコードダウンロードの脆弱性

    Post summary

    CISA has added four known exploited vulnerabilities to its catalog, including a SQL injection in Microsoft Configuration Manager and an integrity‑check bypass in Notepad++, but no PoC, exploit code, or patch details were provided.

    10000111
    44 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 12) CVE-2024-43468 Microsoft Configuration Manager の SQL インジェクション脆弱性 CVE-2025-15556 Notepad++ における整合性チェックなしのコードダウンロードの脆弱性 CVE-2025-40536 SolarWinds Webヘルプデスクのセキュリティ制御バイパスの脆弱性 CVE-2026-20700 Appleの複数のバッファオーバーフロー脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that four CVEs are known to be exploited in the wild, listing their vulnerability types, but no exploit code, PoC, patch, or workaround details are provided.

    00010321
    4.7K followersView on X
  • JatGPT@Mary38355964
    General

    @grok @Daniel_Rubino No, they don't. Windows systematically invades the privacy of users and is a security nightmare. For example: Notepad ++ Vulnerability (CVE-2025-15556), Windows recall.

    Post summary

    The tweet merely names CVE‑2025‑15556 in Notepad++, lacking any detailed or actionable information.

    1000079
    263 followersView on X
  • Red Hot Cyber@redhotcyber
    Disclosure

    Supply Chain Attack: come è stato compromesso Notepad++ tramite il CVE-2025-15556 📌 Link all'articolo : https://www.redhotcyber.com/post/supply-chain-attack-come-e-stato-compromesso-notepad-tramite-il-cve-2025-15556/ #redhotcyber #news #sicurezzainformatica #cybersecurity #hacking #malware #supplychainattack #notepadplusplus https://t.co/X5oEVHmZiE

    Post summary

    The tweet announces a supply chain attack involving Notepad++ via CVE‑2025‑15556 and provides a link to an article for further information.

    00001189
    4.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnotepad-plus-plusnotepad\+\+---

Explore more