The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a Notepad++ issue tracked as CVE-2025-15556. The Notepad++ flaw is a CWE-494 (Download of Code Without Integrity Check) weakness in the WinGUp updater that can allow attackers to intercept or redirect update traffic and deliver a tampered installer, resulting in arbitrary code execution with the victim user’s privileges. CISA’s KEV addition indicates the vulnerability is being actively exploited, and the reporting notes Notepad++ versions prior to 8.8.9 are affected, with 8.8.9+ implementing stronger verification to prevent malicious update packages from being installed.
In the same KEV update, CISA also listed other exploited flaws affecting SolarWinds Web Help Desk (security control bypass), Microsoft Configuration Manager (SQL injection), and Apple devices (buffer overflow), reinforcing that the agency is tracking exploitation across multiple widely deployed enterprise and endpoint products. Separately, Microsoft disputed that newly presented Windows LNK shortcut spoofing techniques constitute vulnerabilities, describing them instead as behaviors arising from how Windows parses conflicting shortcut target fields—this LNK topic is not part of the KEV additions described above and does not materially change the Notepad++ KEV-driven risk picture.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA directed Federal Civilian Executive Branch agencies to remediate CVE-2025-15556 by 2026-03-05 or discontinue use if mitigations were not feasible. The agency also urged organizations to apply vendor patches due to the risk of malware, ransomware, droppers, or backdoors.
Notepad++ remediated CVE-2025-15556 in version 8.8.9 and later by adding cryptographic verification for update packages downloaded by the WinGUp updater. The flaw could allow arbitrary code execution via tampered update traffic.
On 2026-02-12, CISA added CVE-2025-15556 to its Known Exploited Vulnerabilities catalog, citing active exploitation of the Notepad++ WinGUp updater flaw in attacks. The vulnerability affects Windows systems and enables malicious installers to be delivered through intercepted or redirected update traffic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.