Windows 11 Notepad flaw let files execute silently via Markdown links
ID: e764773c-0501-5c65-840e-4d020a3ca214
STIX ID: report--e764773c-0501-5c65-840e-4d020a3ca214
Feed Name: Bleeping Computer
Threat Score
Microsoft fixed a high-severity remote code execution vulnerability (CVE-2026-20841) in Windows 11 Notepad that allowed attackers to trick users into clicking malicious Markdown links which could launch and execute local or remote executables without Windows security warnings; PoC exploits demonstrated file:// and special URI abuses, and Microsoft now shows warnings for non-http(s) links after the February 2026 update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
