Windows Notepad App Remote Code Execution Vulnerability

February 11th, 2026

After using Notepad on Windows for about thirty years, I uninstalled it on Windows 11 because it could interact with Copilot. Even though I uninstalled Copilot, the fact that Notepad had any hook at all to it was creepy and ridiculous.

I now use Notepad3, which is great.

Via: TechSpot:

One of the first-party Microsoft apps that received a hotfix this week is Notepad, which was recently updated with a range of AI features. Tracked as CVE-2026-20841, the remote code execution vulnerability exploited the improper neutralization of special elements used in a command, enabling malicious actors to execute arbitrary, unauthorized code on the host machine over a network.

More: And Now Notepad Is Complex Enough to Support Remote Code Execution

Leave a Reply

You must be logged in to post a comment.