notepad-plus-plus

7 known vulnerabilities in notepad-plus-plus, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-15556 CVSS 7.7 high · actively exploited Notepad++ Download of Code Without Integrity Check Vulnerability

Latest vulnerabilities

  • CVE-2026-86056 CVSS 5.5 medium Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp…
  • CVE-2026-86054 CVSS 7.8 high Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in…
  • CVE-2026-85995 CVSS 7.3 high Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can…
  • CVE-2026-85288 CVSS 6.7 medium Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation…
  • CVE-2026-85279 CVSS 8.6 high Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in…
  • CVE-2026-77605 CVSS 7.8 high Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can…
  • CVE-2025-15556 CVSS 7.7 high · actively exploited Notepad++ Download of Code Without Integrity Check Vulnerability