Description
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user triggers the updater path, but the issue does not provide remote code execution by itself. This issue is fixed in version 8.9.8.
Published: 2026-09-22
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Execution of attacker modified code via updater bypass
Action: Immediate Patch
AI Analysis

Impact

A flaw in the updater and signature verification path of Notepad++ between versions 8.9.7 and earlier allows a modified GUP.exe file to be accepted when its embedded certificate data is still present, despite the Authenticode digest being invalid. An attacker who can replace or inject the updater‑related file can cause Notepad++ to launch attacker‑modified code when the user triggers an update. The vulnerability does not enable remote code execution on its own; it merely permits execution of code that the attacker has already supplied.

Affected Systems

The affected vendor is Notepad++ with the product Notepad++. Affected versions are 8.9.7; the issue is resolved in version 8.9.8. All other releases are not impacted.

Risk and Exploitability

The CVSS score of 7.3 reflects a moderate to high severity risk. EPSS data is not available, so current exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV. Exploitation would require the attacker to first get access to the updater files—either by tampering with a trusted update source or by acting as a local threat actor with write permissions—after which the modified updater can be executed. While the flaw alone does not confer remote code execution, it can be a precursor for attackers who have already compromised the local system or have intercepted update distribution.

Generated by OpenCVE AI on September 22, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Notepad++ to version 8.9.8 or newer to apply the vendor fix (CWE-347).
  • Ensure that the updater files, especially GUP.exe, are obtained from the official release source and verify their integrity before installation (CWE-347).
  • If upgrading is not immediately possible, restrict write access to the Notepad++ installation directory and the updater component to prevent malicious replacement of the GUP.exe file (CWE-347).

Generated by OpenCVE AI on September 22, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Notepad-plus-plus
Notepad-plus-plus notepad++
Vendors & Products Notepad-plus-plus
Notepad-plus-plus notepad++

Tue, 22 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user triggers the updater path, but the issue does not provide remote code execution by itself. This issue is fixed in version 8.9.8.
Title Notepad++: Authenticode verification bypass allows modified updater execution
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Notepad-plus-plus Notepad++
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T17:43:17.068Z

Reserved: 2026-09-04T19:17:36.245Z

Link: CVE-2026-85995

cve-icon Vulnrichment

Updated: 2026-09-22T17:35:40.816Z

cve-icon NVD

Status : Received

Published: 2026-09-22T18:17:23.650

Modified: 2026-09-22T18:17:23.650

Link: CVE-2026-85995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:30:14Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature