Disaster Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines.

Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special elements in commands (CWE-77: Command Injection) and carries a CVSS v3.1 base score of 8.8/10, rated “Important.”

The bug affects the modern Windows Notepad app, available via the Microsoft Store. An unauthorized attacker could exploit it over a network by tricking users into opening a booby-trapped Markdown (.md) file.

Once loaded, a malicious link inside the file prompts the app to handle unverified protocols. Clicking the link triggers Notepad to fetch and execute remote files, injecting arbitrary commands without proper sanitization.

Attackers craft Markdown files with hyperlinks using custom schemes (e.g., mimicking safe protocols but pointing to attacker-controlled servers). When a user opens the file in Notepad and clicks the link, the app processes it naively, leading to command injection.

The payload executes in the logged-in user’s security context, granting attackers the same privileges – from file access to privilege escalation if the user has admin rights.

The patch rolled out via the Microsoft Store for Notepad (build 11.2510+), with full release notes and a direct security update link. Users must update manually or enable auto-updates, as it’s customer action required. Microsoft credits independent researchers Delta Obscura (delta.cyberm.ca) and “chen” for coordinated disclosure.

This flaw underscores risks in everyday apps that handle rich text, such as Markdown, especially as Notepad evolves from a basic editor into a feature-rich tool. While legacy Notepad.exe remains unaffected, the Store version’s popularity amplifies exposure.

Mitigation Steps

  • Update Notepad immediately from the Microsoft Store.
  • Enable automatic app updates in Windows Settings.
  • Avoid opening untrusted Markdown files or clicking links in them.
  • Use an antivirus with behavior-based detection for anomalous protocol handlers.


Link Archive
 
Notepad status:
REDEEMED SAAR!!!

But seriously only a MicroJeet could figure out how to fuck up so hard as to manage to inadvertently slip an RCE vulnerability into fucking NOTEPAD.

Like, curry-muncher, seriously, you want to do the AI developer good Saar so you can grovel at the feet of Elon and friends but you literally cant ship a feature to fucking NOTEPAD.EXE of all fucking things.

Total. Jeet. Deportation. Nope, you’re not “elite human capital”, you’re a bunch of subhuman tiny dick rape apes and you have to go back.
 
Huh, was wondering why Notepad had kept on insisting that I use copilot on there. Guess I should've just went back to legacy version instead of using Notepad++ (Which also had a fucking attack JFC)
Motherfucker. I've looked this up and we can blame the CCP faggots since it was a state-sponsored attack from China, and the author is dipping his toes in politics that seems more like a shitty attempt at virtue signaling from afar. There's also a bunch of other mistakes.

The hosting of the updates got compromised, I'm not sure who or what the host is but both the author of notepad++ and the hosting for the updates jeeted hard. On top of that we don't even know who was targeted and what the payload does. All everyone says so far it targets East Asia countries.
 
who the fuck downloads notepad? What are we specifically going to download next, Solitaire? Minesweeper?
 
I’ve been rifling through no-frills text editors to replace this pile of trash, especially since N++ got owned last week. VSCode used to be ok, but it’s been jeeted to death and it’s an even fatter piece of shit than Quartering.

Been trying Zed for the past few days. On one hand, it’s pretty low-frills and snappy, performance wise. On the other hand, it’s made by Rust-niggers.

What are you guys’ thoughts?
 
Last edited:
who the fuck downloads notepad? What are we specifically going to download next, Solitaire? Minesweeper?
In fairness they went and removed the classic versions of those games in...windows 10 I believe? In favor of shittier app store versions, just like this version of notepad that got redeemed.

So yes, some people will download the old version of those games.
 
This is retarded. Why does an "app" version of notepad even exist? Wait, don't answer that, it's jeets. NOTEPAD MUST BE AN APP SAR NOT APPLICATION THAT IS OBSOLETE SAR.

Notepad.exe serves its purpose just fine.
How hard is it to make a stable, user friendly UI? Even Windows EIGHT didn’t fail THAT BAD.
 
Increasingly happier I swapped to Linux. Everyone raised on Windows and afraid to switch: it's never too late to learn. Ubuntu's pretty normie-friendly.
Im getting closer to it.. Proton really does seem good enough of a wrapper for most games. I do dream of steam's os replacing windows for the more tedious aspects I need windows for.
 
Im getting closer to it.. Proton really does seem good enough of a wrapper for most games. I do dream of steam's os replacing windows for the more tedious aspects I need windows for.
Give it a go honestly. I ragequit windows after RDPing to my Win11 install caused everything to randomly break. And Windows' RDP was basically its only selling point for me, as most of my work is done by using a macbook as a glorified terminal.
I installed arch on a separate SSD, and after realizing I hadn't even booted windows in the 8 months since I installed Arch (even after going through the trouble of adding the Windows GRUB entry), I gloriously dd'd the Windows install. I know like 10 years ago it used to be a joke about Arch being year of the linux desktop, but I was very pleasantly surprised by how well things have come. Things like wifi and bluetooth just work. I turn on my bluetooth keyboard and game controller and it just starts working, shocking right?
Or maybe I'm just not realizing that this is just a testament to how much Windows has been enshittified.

Admittedly, the RDP integration with kde is really jank (at least that's my experience with krdp 6.5), but hey so is Windows 11's. 🤷‍♀️

The only time I've found trouble is with getting old games to work (Fallout 3), but in that case it's easy enough for me to just pull out a Windows laptop and swap some cables over. All modern games have worked perfectly for me (except ones designed to not work on linux like Valorant obviously)
 
Last edited:
The only time I've found trouble is with getting old games to work (Fallout 3), but in that case it's easy enough for me to just pull out a Windows laptop and swap some cables over. All modern games have worked perfectly for me (except ones designed to not work on linux like Valorant obviously)
Honestly I should. All my arguments can really be solved via duel booting. I haven't "enjoyed" windows since xp. I really should just rip the bandaid off. I've nothing to lose but my toolbar not telling me what special groups day it is.
 
Seriously, just download Linux.

If 99% of your time is spent on youtube and the internet, then just get linux. Nothing changes, except it runs smoother, better, faster.

Most people use their computers as glorified Chromebooks. Get one of the normie distros, shit, make the Linux spergs seethe and get an immutable distribution, leave it alone and live your life as an official “not nigger cattle”.
 
Back
Top Bottom