Purple-Ops
Critical RCE Vulnerability in Windows Notepad and RPC Identified
First seen 12 Feb 2026, 21:16 UTC
•
•57.5
Export
Article Content
Browse articles
CVE-2026-20841, a critical vulnerability with a CVSS score of 9.8, affects Windows Remote Procedure Call (RPC) and allows unauthenticated remote code execution. Additionally, a related issue in Windows Notepad, with a CVSS score of 8.8, enables remote code execution via malicious Markdown files. Both vulnerabilities were published on February 10, 2026, with proof of concept released the following day.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-10
CVE-2026-20841 published
2026-02-11
First public PoC released
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows