Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links

Feb 12, 2026 01:06 AM - 3 months ago 87179

Emma Roth

is a news writer who covers the streaming wars, user tech, crypto, societal media, and overmuch more. Previously, she was a writer and editor astatine MUO.

Microsoft has fixed a superior information vulnerability affecting Markdown files successful Notepad. In the company’s Tuesday spot notes, Microsoft says a bad character could transportation retired a distant codification execution onslaught by tricking users “into clicking a malicious nexus wrong a Markdown record opened successful Notepad,” arsenic reported earlier by The Register.

Clicking the nexus would “launch unverified protocols,” allowing attackers to remotely load and execute malicious files connected a victim’s computer, according to the spot notes. Microsoft says location isn’t immoderate grounds of attackers exploiting the Notepad vulnerability (CVE-2026-20841) successful the wild, but it issued a hole for the flaw successful its Tuesday patch.

Microsoft initially added support for Markdown, a plaintext formatting language, to Notepad connected Windows 11 past May. The move contributed to criticism that Microsoft is filling its operating strategy pinch bloatware, including by stuffing caller features and AI capabilities into apps for illustration Notepad and Paint.

Notepad isn’t the only matter editor that has faced information issues recently, as the third-party Notepad++ app disclosed that immoderate users whitethorn person downloaded a malicious update linked to Chinese state-sponsored attackers.

Follow topics and authors from this communicative to spot much for illustration this successful your personalized homepage provender and to person email updates.

More