Windows Notepad App Remote Code Execution Vulnerability
February 11th, 2026After using Notepad on Windows for about thirty years, I uninstalled it on Windows 11 because it could interact with Copilot. Even though I uninstalled Copilot, the fact that Notepad had any hook at all to it was creepy and ridiculous.
I now use Notepad3, which is great.
Via: TechSpot:
One of the first-party Microsoft apps that received a hotfix this week is Notepad, which was recently updated with a range of AI features. Tracked as CVE-2026-20841, the remote code execution vulnerability exploited the improper neutralization of special elements used in a command, enabling malicious actors to execute arbitrary, unauthorized code on the host machine over a network.
More: And Now Notepad Is Complex Enough to Support Remote Code Execution
