Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links
Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the company’s Tuesday patch notes, Microsoft says a bad actor could carry out a remote code execution attack by tricking users “into clicking a malicious link inside a Markdown file opened in Notepad,” as reported earlier by The Register.
Clicking the link would “launch unverified protocols,” allowing attackers to remotely load and execute malicious files on a victim’s computer, according to the patch notes. Microsoft says there isn’t any evidence of attackers exploiting the Notepad vulnerability (CVE-2026-20841) in the wild, but it issued a fix for the flaw in its Tuesday patch.
Microsoft initially added support for Markdown, a plaintext formatting language, to Notepad on Windows 11 last May. The move contributed to criticism that Microsoft is filling its operating system with bloatware, including by stuffing new features and AI capabilities into apps like Notepad and Paint.
Notepad isn’t the only text editor that has faced security issues recently, as the third-party Notepad++ app disclosed that some users may have downloaded a malicious update linked to Chinese state-sponsored attackers.
You may be interested

Rays Set For New $2.3B Stadium Project After County, City Approve Financing Plan
new admin - Aug 29, 2026[ad_1] NEWYou can now listen to Fox News articles! The Tampa Bay Rays got county approval Friday on a financing…
Inflation still high as Iran war hits 6 months and Trump’s tariffs continue
new admin - Aug 29, 2026Federal Reserve Chair Kevin Warsh says the central bank may be forced to act if inflation does not cool. This…
Dolly Parton “loved being called the book lady,” charity president remembers
new admin - Aug 29, 2026Tonight, Nashville's Grand Ole Opry will remember Dolly Parton in a star-studded tribute. The beloved country singer was also celebrated…


























