CVE detail
CVE-2025-15556 — Notepad++ Download of Code Without Integrity Check Vulnerability
Published 2026-02-12 · Modified 2026-02-12 · Source kev
HIGH
severity
CVSS-derived band
0.0127
EPSS probability
exploitation probability, 30d
67.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2026-03-05
⚠ Actively exploited in the wild — CISA KEV listed 2026-02-12, federal remediation due 2026-03-05.
Description
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References