Theregister
Vulnerability in Notepad's Markdown Feature Allows Remote Code Execution
First seen 11 Feb 2026, 19:30 UTC
•



+55
•56.1
Export
Article Content
Browse articles
Researchers have discovered a vulnerability in Notepad's newly added Markdown support that can be exploited for remote code execution (RCE). This flaw, tracked as CVE-2026-20841 with a severity score of 8.8, was addressed in Microsoft's latest Patch Tuesday updates. The exploitation requires social engineering tactics, making it less severe than other vulnerabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-10
CVE-2026-20841 published
2026-02-11
First public PoC released
More articles in this cluster
Continue Reading
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Massive Data Breach at Change Healthcare Affects 190 Million Americans
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group
US Indicts Russian Nationals for $62M Cybercrime Scheme Targeting Critical Infrastructure