
In this spooky Friday the 13th episode of IT SPARC Cast - CVE of the Week, @john_Video and @loudoggeek break down a shocking vulnerability: CVE-2026-2841, a Remote Code Execution (RCE) flaw in the modern Windows 11 Notepad application distributed via the Microsoft Store. Yes — even Notepad isn’t safe anymore. This vulnerability stems from a command injection flaw in the modern Windows 11 Store version of Notepad (11.x prior to patch). The issue allows malicious .md (Markdown) files containing crafted links or interactive content to execute arbitrary code when opened and clicked by a user. With a CVSS score of 8.8, this vulnerability becomes especially dangerous when chained with other exploits. Youtube Episode 24 - https://youtu.be/gdR6Xawy0c4&utm_source=x&utm_medium=organic_social&utm_campaign=it_sparc_cast&utm_content=post YouTube Channel - https://www.youtube.com/@sparccast Apple Podcast Link - https://podcasts.apple.com/us/podcast/it-sparc-cast/id1765417728 Spotify Link - https://open.spotify.com/show/6bzVql2gpV6aVqX8oAAPls Amazon Podcast Link - https://music.amazon.com/podcasts/ea33693d-f555-4a7c-8c36-d321ab5cfed2/it-sparc-cast?ref=dm_sh_MPp9hVbtUJhlG3cN3xhfN5YN3 Acast Link - https://shows.acast.com/it-sparc-cast
Post summary
The post explains CVE‑2026‑2841, a command‑injection RCE flaw in the Windows 11 Store Notepad that can be triggered by malicious Markdown files, without mentioning active exploitation, patches, or a PoC.

