logo

CVE-2026-20841: Windows Notepad RCE Fixed in Microsoft’s February Patch Tuesday Release

ID: b4a8cca9-0a5f-5aa4-9739-ca403b8e244e

STIX ID: report--b4a8cca9-0a5f-5aa4-9739-ca403b8e244e

Feed Name: SOC Prime Blog

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Microsoft’s February 2026 Patch Tuesday addresses CVE-2026-20841, an 8.8-rated remote code execution vulnerability in the modern Windows Notepad (Store) app that can be exploited when a user opens a crafted Markdown (.md) file and clicks a malicious link; organizations should update Notepad to build 11.2510+ via the Microsoft Store, enable automatic app updates, and avoid opening or clicking links in untrusted Markdown files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.