For over four decades, Windows Notepad has been the basic text editor of choice for many a discerning PC user. In recent years, though, Microsoft has been steadily adding all kinds of features to it, turning it from a barebones word processor into something decidedly more complex. Unfortunately, the addition of formatting and tables now includes one more feature: a remote code execution vulnerability that could let hackers run all kinds of nasty stuff on your PC.
Microsoft acknowledges the issue in its security update guide, snappily labelled as CVE-2026-20841. With a common vulnerability base score of 8.8 and temporal score of 7.7, it's rated as a 'high' security problem.
This security vulnerability isn't an issue with Markdown itself, just how Notepad renders it, but exactly how Microsoft will fix this isn't clear at this stage. For now, though, you can avoid the problem entirely by sticking to some important procedures: Do not download any file that you can't verify the integrity of its source and never click on a random link.
The good news is that there is currently no known exploitation of this vulnerability doing the rounds out in the wild, and even if there was, it's pretty straightforward to avoid putting your PC into harm's way. But given the simplicity of the hack, you'd think that Microsoft would have already thought about the possibility of it before going all willy-nilly with expanding Notepad's feature set.










English (US) ·