Notepad++ has released version 8.9.2 to fix security flaws that allowed a China-linked threat actor to hijack its update mechanism and deliver targeted malware. The update introduces a “double lock” system that verifies both the signed installer from GitHub and the signed XML update metadata from the official server, making the update process significantly harder to tamper with.
Additional security improvements were made to the WinGUp auto-updater, including removing libcurl.dll to prevent DLL side-loading, disabling insecure cURL SSL options, and restricting plugin management to binaries signed with the same certificate.
The release also fixes a high-severity vulnerability (CVE-2026-25926) that could enable arbitrary code execution via an unsafe search path issue.
The fixes follow a 2025 hosting provider breach that allowed attackers to redirect update traffic and distribute a backdoor called Chrysalis, attributed to the Lotus Panda group.
Users are advised to update to Notepad++ 8.9.2 and download installers only from the official website.

















Comments