Junglewise Threat Intelligence

CVE-2026-85995: Notepad++ Authenticode signature verification bypass

CVE-2026-85995 · Severity: high · CVSS 7.3 · Published 2026-09-22

Technologies: Notepad++. Vendors: Notepad++.

Executive brief

Notepad++ is a text editor used by developers worldwide. An attacker who can locally modify or replace the updater file can trick Notepad++ into running malicious code when a user checks for updates. This requires local file access and user action to trigger, but can lead to code execution on the developer's machine.

Technical details

The updater signature verification in Notepad++ versions 8.9.7 through 8.9.8 fails to properly validate the Authenticode digest of the GUP.exe executable, accepting modified binaries that retain valid certificate metadata. An attacker with local file system access can replace the updater executable with a malicious variant, which will be executed when the user triggers the automatic update check. This was patched in version 8.9.8.

Affected products

  • Notepad++ Notepad++ 8.9.7 to 8.9.8

Timeline

  • 2026-09-22: disclosed
  • 2026-08-23: patched: Fix released in version 8.9.8

References