OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-85995

HIGH · CVSS 7.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Notepad++ versions 8.9.7 to 8.9.8 are vulnerable due to a flaw in the updater and signature verification process, allowing an attacker to replace the GUP.exe file with a modified version that retains invalid certificate metadata. This could lead to the execution of attacker-controlled code when users initiate the update process, posing a significant security risk. Users and organizations utilizing affected versions should prioritize upgrading to version 8.9.8 to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85995
Severity
HIGH
CVSS
7.3
EPSS
0.12%

Original NVD Description

Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user triggers the updater path, but the issue does not provide remote code execution by itself. This issue is fixed in version 8.9.8.