Update Path Vulnerability in Notepad++ Source Code Editor
CVE-2026-85995
7.3HIGH
What is CVE-2026-85995?
Notepad++ is an open-source source code editor that has encountered a vulnerability affecting its updater mechanism. The flaw allows the updater and signature verification process to accept a tampered GUP.exe file that retains its certificate metadata, even if the Authenticode digest is invalid. If an attacker manages to replace or inject a malicious updater file, this could lead to executing modified code during the updater's operation. While this vulnerability does not inherently allow for remote code execution, it poses significant risks for users who may unwittingly activate the compromised updater. The issue has been addressed in version 8.9.8.
Affected Version(s)
notepad-plus-plus < 8.9.8
