CVE-2026-20841Disclosure(microsoft / windows_notepad)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 124 mentions and remains active

Immediate actions

  • Patch microsoft windows_notepad systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_notepad

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 367 mentions across 38 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 24 signals
  • PoC mentioned or linked in 47 signals
  • Patch or workaround mentioned in 114 signals
  • Technical details provided in 225 signals
  • Disclosure: 115 classified signals
  • General: 115 classified signals
  • Peaked 36d ago at 124 mentions (2026-02-11); latest day: 1
  • 367 total mentions across 38 days

Affected systems

Vendors
Products
windows_notepad

Deep dive

Activity timeline367 mentions / 38d
0316293124Mentions · 2026-02-10: 13Mentions · 2026-02-11: 124Mentions · 2026-02-12: 105Mentions · 2026-02-13: 28Mentions · 2026-02-14: 8Mentions · 2026-02-15: 5Mentions · 2026-02-16: 13Mentions · 2026-02-17: 13Mentions · 2026-02-18: 1Mentions · 2026-02-19: 4Mentions · 2026-02-20: 5Mentions · 2026-02-22: 2Mentions · 2026-02-24: 2Mentions · 2026-02-25: 8Mentions · 2026-02-26: 3Mentions · 2026-02-27: 3Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-08: 6Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Mentions · 2026-03-14: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-03: 1Mentions · 2026-04-05: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-05-06: 1Mentions · 2026-05-13: 1Mentions · 2026-05-15: 1Mentions · 2026-07-31: 1Mentions · 2026-08-05: 1Mentions · 2026-08-09: 1PoC Mentioned / Linked · 2026-02-11: 13PoC Mentioned / Linked · 2026-02-12: 18PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-14: 2PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-20: 3PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-27: 2PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-06: 1Exploit Tool / Code · 2026-02-11: 8Exploit Tool / Code · 2026-02-12: 9Exploit Tool / Code · 2026-02-14: 1Exploit Tool / Code · 2026-02-16: 1Exploit Tool / Code · 2026-02-20: 1Exploit Tool / Code · 2026-02-27: 2Exploit Tool / Code · 2026-04-29: 1Exploit Tool / Code · 2026-05-06: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-13: 1Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-11: 33Patch / Workaround · 2026-02-12: 39Patch / Workaround · 2026-02-13: 13Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 4Patch / Workaround · 2026-02-16: 4Patch / Workaround · 2026-02-17: 3Patch / Workaround · 2026-02-19: 3Patch / Workaround · 2026-02-20: 3Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-02-10: 9Technical Details · 2026-02-11: 69Technical Details · 2026-02-12: 73Technical Details · 2026-02-13: 16Technical Details · 2026-02-14: 3Technical Details · 2026-02-15: 3Technical Details · 2026-02-16: 6Technical Details · 2026-02-17: 9Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 4Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 7Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 3Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-22: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-13: 1Technical Details · 2026-08-05: 102-1002-1302-1602-1902-2402-2703-0803-1403-2104-0104-2805-1308-0508-09
Signal classification7 categories
Disclosure
11531.3%
General
11531.3%
Patch
9525.9%
PoC
369.8%
Active Exploitation
30.8%
Exploit
20.5%
Referenced assets133 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-1013
Disclosure7General5Patch1
2026-02-11124
Disclosure39General45Patch28PoC12
2026-02-12105
Disclosure29False Positive1General23Patch37PoC15
2026-02-1328
Disclosure7General8Patch12PoC1
2026-02-148
General5Patch1PoC2
2026-02-155
Disclosure1General1Patch3
2026-02-1613
Disclosure4General4Patch4PoC1
2026-02-1713
Active Exploitation1Disclosure7General4Patch1
2026-02-181
General1
2026-02-194
Disclosure1General1Patch2
2026-02-205
General1Patch1PoC3
2026-02-222
General2
2026-02-242
Disclosure2
2026-02-258
Disclosure5General1Patch2
2026-02-263
Active Exploitation1Disclosure1Patch1
2026-02-273
Exploit1General1PoC1
2026-03-061
Disclosure1
2026-03-072
General1Patch1
2026-03-086
Disclosure2General3Patch1
2026-03-121
Disclosure1
2026-03-132
Active Exploitation1Disclosure1
2026-03-141
Disclosure1
2026-03-181
Disclosure1
2026-03-192
Disclosure1General1
2026-03-211
General1
2026-03-221
Disclosure1
2026-03-301
General1
2026-04-011
Disclosure1
2026-04-031
General1
2026-04-051
General1
2026-04-281
General1
2026-04-291
Exploit1
2026-05-061
PoC1
2026-05-131
Disclosure1
2026-05-151
General1
2026-07-311
General1
2026-08-051
Disclosure1
2026-08-091
General1
Full discourse20 posts
  • vx-underground@vxunderground
    Disclosure

    The new AI powered Notepad on Windows 11 was found having a Remote Code Execution 0day Hot take: text editors don't need network functionality https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    Post summary

    Microsoft announced a Remote Code Execution zero‑day in the new AI‑powered Notepad for Windows 11, as detailed in the MSRC advisory.

    52356293.4K299160.5K
    421.4K followersView on X
  • Co11ateral@co11ateral
    Disclosure

    CVE-2026-20841 - Windows Notepad App Remote Code Execution Vulnerability For nearly thirty years, notepad.exe was treated as a simple utility. It functioned as a basic Win32 text editor designed solely to display text. A CVSS score of 8.8 for an application intended only for viewing data is a departure from the principle of least privilege. The vulnerability allows an attacker to trick a user into clicking a malicious link embedded in a Markdown file opened in Notepad. Doing so can trigger untrusted protocols, leading to the download and execution of remote content. #dfir #blueteam #pentest #redteam #cve #notepad

    Post summary

    CVE-2026-20841 exposes a remote code execution flaw in Windows Notepad, enabling attackers to trick users into clicking malicious links in Markdown files that trigger the download and execution of remote content.

    27227441.1K434144.2K
    1.5K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    Ladies and gentlemen - here is a Notepad* RCE you've always wondered whether it was possible. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 *Well, the modern, AI-powered one.. Who could have thought that with more features you bring more bugs.

    Post summary

    The tweet announces a Notepad RCE (CVE-2026-20841) and provides a link to Microsoft's patch advisory; no PoC, exploit code, or active exploitation is mentioned.

    8871264117077.6K
    8.3K followersView on X
  • ϻг_ϻε@steventseeley
    General

    Literally every old school hacker out there dreamed of achieving a find like this: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    Post summary

    The tweet merely links to the Microsoft MSRC page for CVE‑2026‑20841, offering no additional context, exploitation details, or mitigation information.

    643335322340.3K
    22.6K followersView on X
  • NullSecurityX@NullSecurityX
    General

    CVE-2026-20841 - Windows notepad.exe RCE #BugBounty #CyberSecurity https://t.co/MqyS7JJaWY

    Post summary

    The tweet announces CVE‑2026‑20841, labeling it as a Windows Notepad RCE vulnerability, but provides no PoC, exploit details, or mitigation information.

    339036615722.3K
    9.8K followersView on X
  • H4RUK7 KIRA 🇯🇵🇨🇵@h4ruk7
    PoC

    CVE-2026-20841-POC REMOTE CODE EXECUTION VULNERABILITY IN NOTEPAD VERSION 11 @mrphilghana @RedHatPentester https://t.co/b0oQKJMTei

    Post summary

    A proof‑of‑concept for a remote code execution vulnerability in Notepad v11 has been posted via a link, indicating the issue exists but no patch or active exploitation has been reported.

    147330119920.7K
    8.6K followersView on X
  • Niebezpiecznik@niebezpiecznik
    Patch

    Brzmi jak żart z 2003, a to świeża historia: w aplikacji Windows Notepad wykryto lukę, która pozwala na zdalne odpalenie kodu (RCE: CVE-2026-20841). Notatnik da się skłonić do wykonania polecenia, którego ❌ nie powinien. Scenariusz jest banalny: ofiara otwiera spreparowany plik .md (Markdown) i klika link w jego treści. To wystarczy, żeby uruchomić w systemie cudzy kod. ✅ Poprawka już jest (wypuszczona kilka dni temu). Co robić, jak żyć? 👇

    Post summary

    A recently discovered RCE vulnerability in Windows Notepad (CVE‑2026‑20841) is mitigated by a patch released a few days ago; no evidence of exploitation or exploit code is presented.

    232324086884.6K
    174.1K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Windows Notepad App Remote Code Execution Vulnerability PoC, https://github.com/BTtea/CVE-2026-20841-PoC

    Post summary

    A Proof of Concept for a Windows Notepad Remote Code Execution vulnerability is shared via a GitHub link.

    548223919220.8K
    151.3K followersView on X
  • Tom Warren@tomwarren
    Disclosure

    Notepad was once a lightweight text editor in Windows, but Microsoft has increasingly been adding features to it in recent years. The new Markdown support has led to a Remote Code Execution flaw 😬 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 https://t.co/tw1nNpNLps

    Post summary

    The tweet announces Microsoft Notepad’s new Markdown‑enabled remote code execution flaw (CVE‑2026‑20841) by linking to the official Microsoft advisory.

    1748103654479.6K
    310.7K followersView on X
  • Ben Visness@its_bvisness
    Disclosure

    I wouldn’t have thought it possible, but Microsoft managed to put a remote code execution vulnerability…in Notepad. At this point they have to be doing it on purpose…right? https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    Post summary

    A user highlights Microsoft's discovery of a remote code‑execution vulnerability in Notepad and links to the official advisory, but does not provide additional technical or mitigation details.

    132073874065.9K
    3.8K followersView on X
  • Trond Eirik Haavarstein@xenappblog
    Patch

    Notepad CVE-2026-20841. Make sure to push to all Devices in @MSIntune to remediate. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 https://t.co/IoCwzYLDoX

    Post summary

    The tweet highlights Microsoft’s patch for the Notepad vulnerability CVE‑2026‑20841 and urges administrators to deploy the update through Intune.

    931117818017.2K
    9.4K followersView on X
  • Cyber Security News@The_Cyber_News
    Patch

    🚨 Windows Notepad Vulnerability Allows Attackers to Execute Code Remotely Source: https://cybersecuritynews.com/windows-notepad-rce-vulnerability/ Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. The bug affects the modern Windows Notepad app, available via the Microsoft Store. An unauthorized attacker could exploit it over a network by tricking users into opening a booby-trapped Markdown (.md) file. Once loaded, a malicious link inside the file prompts the app to handle unverified protocols. Clicking the link triggers Notepad to fetch and execute remote files, injecting arbitrary commands without proper sanitization. #cybersecuritynews #notepad #windows

    Post summary

    Microsoft patched a critical RCE vulnerability in Windows Notepad (CVE-2026-20841) that could be triggered by a malicious Markdown file. No active exploitation or PoC details were reported.

    770142106522.3K
    48.0K followersView on X
  • Florian Roth ⚡️@cyb3rops
    Disclosure

    CVE-2026-20841 (Notepad) - why I’m not excited (yet) - If the POCs I’ve seen so far are actually representative of what this CVE describes, the main trigger is Ctrl+Click on a link inside a Markdown file opened in Notepad - Notepad launches the registered URI/protocol handler without scheme filtering - Code executes in the user context, so it’s RCE but only with explicit user interaction Practical exploitation looks inefficient: - you need a victim to open a .md in Notepad, switch to Markdown view, then Ctrl+Click - anything file-based still runs into MoTW / SmartScreen warnings - to make it reliable you typically end up chaining into protocol handler quirks, WebDAV/UNC tricks, or another bug Detection is straightforward: - look for uncommon child processes spawned from notepad.exe - notepad.exe should have a very small and boring process tree in normal use (maybe browser/help stuff, not cmd/powershell/mshta/etc.) - parent-child + command line is usually enough to build a decent rule Patch it, sure. But in its current form it’s mostly a click-driven protocol invocation issue with a loud headline attached. If I were an attacker I would keep using malicious LNK files. They require fewer clicks.

    Post summary

    The post explains CVE-2026-20841’s RCE via Notepad’s Markdown view, highlights the low likelihood of efficient exploitation, outlines detection methods, and notes that a patch is available.

    22811525445.6K
    215.8K followersView on X
  • Jordan Benzing@JordanTheITguy
    Patch

    So I was reading the Patch Notes, as one does on Patch Tuesday.... and.... and.... https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 Notepad... you know that thing on every. single. windows. device. ever. Has an 8.8 RCE vulnerability in it. Related to... rendering markdown. Amazing. #PatchTuesady

    Post summary

    Microsoft released a patch for CVE-2026-20841, an 8.8‑scored RCE in Notepad’s markdown rendering, and the advisory provides details and remediation.

    72221363814.0K
    4.5K followersView on X
  • yurikrupenin.bsky.social@turbojedi
    General

    Microsoft родненькая https://www.cve.org/CVERecord?id=CVE-2026-20841 https://t.co/pNoFzpSQDN

    Post summary

    The tweet merely references CVE-2026-20841 without providing any further information about exploitation, patches, or technical details.

    1054178510.5K
    28.1K followersView on X
  • PatchPoint.Official@_patchpoint_
    PoC

    Notepad RCE (CVE-2026-20841) is getting a lot of attention. This is part of the content provided through our subscription. Check out our simple analysis and judge for yourself.😀 https://github.com/patchpoint/CVE-2026-20841 #notepad #RCE

    Post summary

    The post highlights a CVE-2026-20841 RCE vulnerability in Notepad and shares a GitHub link that likely contains a proof‑of‑concept, but it offers no evidence of active exploitation, patches, or detailed technical data.

    1282844226.8K
    428 followersView on X
  • Sekurak@Sekurak
    Disclosure

    Tego jeszcze nie grali. Poważna podatność windowsowym notepadzie (poważna, czyli: remote code execution - wykonanie wrogiego kodu w Windows) ❌ Opis podatności CVE-2026-20841 może wyglądać na pierwszy rzut dość enigmatycznie: "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network." ❌... ale sprowadza się do otwarcia przez ofiarę odpowiednio spreparowanego pliku .md (markdown) i kliknięcia tam linku Podatność została załatana kilka dni temu.

    Post summary

    The post details a remote code execution flaw in Windows Notepad triggered by a specially crafted markdown file, confirms the technical nature of the vulnerability, and notes that a patch has already been deployed.

    7711011813.0K
    42.1K followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Disclosure

    CVE-2026-20841 RCE on Notepad 🤔 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    Post summary

    Microsoft announced CVE-2026‑20841, a remote code execution flaw in Notepad, and provided a link to the official update guide.

    362843113.5K
    77.1K followersView on X
  • TrendAI Zero Day Initiative@thezdi
    Patch

    CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad - The TrendAI Research team takes a deep dive into this recently patched file parsing bug to show you root cause, source code walk through, and provide detection guidance. Read the details at https://www.zerodayinitiative.com/blog/2026/2/19/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad

    Post summary

    TrendAI Research discusses the recently patched Notepad vulnerability CVE-2026-20841, providing root‑cause analysis, a source code walkthrough, and detection guidance, with no PoC or active exploitation evidence reported.

    2122573413.0K
    85.5K followersView on X
  • PatRyk@Patrosi73
    Disclosure

    i got my first ever CVE acknowledgement today! and it's on a Windows Notepad RCE of all things :D CVE-2026-20841 this wouldve been the second ever notepad CVE but MSRC decided to classify it under the first one from a month back it shouldve been seperate imo but im still glad :) https://t.co/C7T3EODo6V

    Post summary

    The user announces the first acknowledgment of CVE‑2026‑20841, which is a Windows Notepad remote code execution vulnerability, marking a new vulnerability disclosure.

    8308681.4K
    2.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftwindows_notepad---

Explore more