CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 399

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

A command injection vulnerability in Windows Notepad allows remote code execution through malicious Markdown files with specially crafted links. The flaw stems from insufficient validation of link protocols, enabling attackers to execute arbitrary commands in the victim's security context when a user clicks a malicious link in a .md file opened in Notepad. The vulnerability was discovered by researchers at Delta Obscura and has been patched.

Why it matters: Organizations should patch Windows Notepad to prevent arbitrary command execution if users open untrusted Markdown files and click embedded links.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

A command injection vulnerability in Windows Notepad allows remote code execution through malicious Markdown files with specially crafted links. The flaw stems from insufficient validation of link protocols, enabling attackers to execute arbitrary commands in the victim's security context when a user clicks a malicious link in a .md file opened in Notepad. The vulnerability was discovered by researchers at Delta Obscura and has been patched.

Why it matters: Organizations should patch Windows Notepad to prevent arbitrary command execution if users open untrusted Markdown files and click embedded links.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary