logo

Notepad's new Markdown powers served with a side of remote code execution

ID: 9d55d124-a990-592a-b9ce-4d33baec739e

STIX ID: report--9d55d124-a990-592a-b9ce-4d33baec739e

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-02-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers disclosed CVE-2026-20841, a remote code execution vulnerability in Windows Notepad's Markdown support (CVSS 8.8) that can be triggered when a user opens a Markdown file and clicks a malicious link which launches unverified protocols; Microsoft issued patches and stated there are no known active exploits, but the flaw poses caution due to Notepad's widespread default presence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.