#VU122564 Command Injection in Windows Notepad - CVE-2026-20841
Published: February 10, 2026 / Updated: February 13, 2026
Windows Notepad
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation in Windows Notepad App. A remote attacker can trick a victim into clicking a malicious link inside a Markdown file opened in Notepad and execute arbitrary commands.