Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user triggers the updater path, but the issue does not provide remote code execution by itself. This issue is fixed in version 8.9.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-347"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85995.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.9.8"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85995.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"34319370620440211396916763813597334425",
"200510675093863324685858141061894608638",
"45205314674656805979129340213135608629"
],
"threshold": 0.9
},
"id": "CVE-2026-85995-8505807c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/9edf40f725ce62b26c454905e39f0f7fdbbb3ffa",
"target": {
"file": "PowerEditor/src/MISC/Common/verifySignedfile.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"65330268006222325934639712768205878311",
"80349932605788547222834302044341656963",
"336528661421398330569919609483424347924",
"93185596729165514872049697441124288721",
"120573383757213678937586316331586926303",
"92327619621187041231786326835367927557",
"63808274226000357542652906563865968260",
"111680901276236710426252717752807166183",
"95489193778397442553787839628238586458",
"139381208456344786996938901693588364816"
],
"threshold": 0.9
},
"id": "CVE-2026-85995-d5d7063f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/9edf40f725ce62b26c454905e39f0f7fdbbb3ffa",
"target": {
"file": "PowerEditor/src/MISC/Common/verifySignedfile.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "291376187629756796608909596687116908767",
"length": 6749
},
"id": "CVE-2026-85995-e825e422",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/9edf40f725ce62b26c454905e39f0f7fdbbb3ffa",
"target": {
"file": "PowerEditor/src/MISC/Common/verifySignedfile.cpp",
"function": "SecurityGuard::verifySignedBinary"
}
}
]
"2026-09-24T08:26:13Z"