Microsoft has released an urgent update to patch a severe vulnerability in Windows Notepad, identified as CVE-2026-20841.
The Security Risk The flaw allowed attackers to perform Remote Code Execution (RCE). To trigger the exploit, a user simply had to click a malicious link embedded within a Markdown file opened in the editor. Once clicked, the link could grant attackers control over the system.
Is This Being Exploited? According to Microsoft, there is currently no evidence that this vulnerability has been actively exploited by hackers in the wild.
How to Stay Safe The patch is included in Notepad version 11.2510 and later. Users are advised to:
- Open the Microsoft Store.
- Navigate to Library.
- Click Get updates to ensure Notepad is running the latest version.
Promptly updating your software remains the most effective way to prevent these types of security breaches.


