Microsoft patches Windows 11 Notepad security flaw – Markdown issues could have let hackers slip in malware without warning


  • Microsoft fixes Windows 11 Notepad RCE bug CVE-2026-20841
  • The vulnerability exploited Markdown links to execute malicious code with user permissions
  • Patch Tuesday update fixes the issue; versions 11.2510 and earlier remain vulnerable

Microsoft has fixed an RCE (Remote Code Execution) bug in Windows 11 Notepad that could have allowed threat actors to run malware locally without the operating system even prompting the user.

Notepad is one of the oldest programs on Windows, having been around since its inception – however it has evolved over the years, and with Windows 11 it now supports the Markdown format, which uses symbols for formatting – for example, adding an asterisk before and after a word makes it italic, and two stars make it bold.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top