Security vulnerability in Notepad++

A critical security vulnerability in the integrated update function of the open-source software Notepad++ allowed attackers to deliver manipulated updates and install malware between June and December 2025. According to the current state of the investigation, manipulated updates were apparently only delivered to selected targets. The focus was primarily on organizations with political or economic interests in South Asia.
Nevertheless, if you are using Notepad++, we strongly recommend that you update the software to the latest version 8.9.1 (release date: January 26, 2026) immediately. To do this, please download the latest installation file directly from the official Notepad++ website (https://notepad-plus-plus.org/) and do not use the integrated update function for the update.
Recommended procedure in detail:
- First uninstall the existing installation of Notepad++.
- Download the latest version from the official Notepad++ website.
- Install the latest version of Notepad++.
If your system behaves strangely or you receive warning messages from Windows Defender, for example, please contact the ServiceDesk immediately. If you have any questions, please also contact the colleagues.
You can reach the ServiceDesk at:
Hotline: -2000
E-Mail: itsupportuni-mannheim.de
Teams: „IT-Support“
