Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely
ID: c54e2314-7cbb-5e7e-97af-b6ea28daf7a1
STIX ID: report--c54e2314-7cbb-5e7e-97af-b6ea28daf7a1
Feed Name: cybersecurityNews.com
Threat Score
Microsoft disclosed and patched CVE-2026-20841, a critical remote code execution flaw (CVSS 8.8) in the Microsoft Store version of Notepad where crafted Markdown hyperlinks using custom protocol handlers can trigger command injection and remote file execution when a user opens a malicious .md file and clicks the link; Microsoft released a fix (Notepad build 11.2510+) and advises updating, avoiding untrusted Markdown files, and enabling app auto-updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
