logo

Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely

ID: c54e2314-7cbb-5e7e-97af-b6ea28daf7a1

STIX ID: report--c54e2314-7cbb-5e7e-97af-b6ea28daf7a1

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft disclosed and patched CVE-2026-20841, a critical remote code execution flaw (CVSS 8.8) in the Microsoft Store version of Notepad where crafted Markdown hyperlinks using custom protocol handlers can trigger command injection and remote file execution when a user opens a malicious .md file and clicks the link; Microsoft released a fix (Notepad build 11.2510+) and advises updating, avoiding untrusted Markdown files, and enabling app auto-updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.