Notepad ++ has released a security update to address vulnerabilities exploited by Chinese hackers. The vulnerabilities allowed abuse of the update mechanism to distribute malware to targets.

The update 8.9.2 incorporates what maintainer Don Ho describes as a “double-locking” design, aimed at making the update process “resilient and essentially unexploitable.” This involves verifying the signed installer downloaded from GitHub (implemented in version 8.8.9 and later) and verifying the signed XMLreturned by the update server at notepad-plus-plus.org.
See also: Serious vulnerabilities in popular VSCode extensions
Notepad++: Update and general security enhancement
Notepad++ has also introduced other changes to WinGUp, the auto-updater component, to enhance security:
– Removing libcurl.dll to eliminate the risk of DLL side-loading
– Remove two insecure cURL SSL options: CURLSSLOPT_ALLOW_BEAST and CURLSSLOPT_NO_REVOKE
– Restrict plugin management execution to programs signed with the same certificate as WinGUp
The update also addresses a high-severity vulnerability (CVE-2026-25926, CVSS score: 7.3) that could lead to code execution within the context of the current application.

“There is an Unsafe Search Path (CWE-426) when starting Windows Explorer without an absolute executable path,” Ho explained. “This could allow the execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain circumstances, this could lead to code execution within the context of the current application.”
See also: Keenadu: New backdoor detected in Android firmware
It is worth noting that Notepad++ recently revealed a breach at the hosting provider level, which allowed threat actors to hijack update traffic and redirect requests from certain users to malicious servers (for distributing infected updates). The issue was detected in early December 2025.
According to Rapid7 and Kaspersky, the forged updates allowed attackers to distribute a backdoor, dubbed Chrysalis. This supply chain incident, tracked as CVE-2025-15556 (CVSS score: 7.7), has been attributed to a hacker group with connections to China (Lotus Panda).
See also: OpenClaw: Infostealer steals configuration files and gateway tokens

Notepad++ users are advised to update to version 8.9.2 and ensure that installers are downloaded from the official domain.
