Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-release

ThreatsDay Bulletin Highlights Microsoft Notepad Markdown Link RCE (CVE-2026-20841)

Updated 3mo agoFirst seen Feb 13, 20263 sources

Microsoft patched a Windows Notepad command-injection vulnerability, CVE-2026-20841 (CVSS 8.8), that can lead to remote code execution when a user opens a Markdown file in Notepad and clicks a crafted malicious link. The issue is described as improper neutralization of special elements used in a command, enabling an attacker to trigger execution of remote or local payloads in the security context of the logged-in user. Public proof-of-concept examples indicate the flaw can be exercised using Markdown file:// links pointing to executables (e.g., file://C:/windows/system32/cmd.exe) and other special URI handlers.

The reporting appears as part of a broader weekly “ThreatsDay” roundup that also references other, separate security stories (e.g., AI prompt injection/RCE themes and other malware/exploit items), but the concrete, actionable item consistently detailed is the Notepad Markdown-link RCE and its patch. A separate “Daily Cyber News” post discusses Microsoft releasing fixes for multiple exploited flaws across widely deployed products, but it does not specifically corroborate the Notepad CVE or the Markdown-link exploitation path described in the roundup, making it contextually related to Microsoft patching activity but not the same discrete vulnerability story.

Share:
ThreatsDay Bulletin Highlights Microsoft Notepad Markdown Link RCE (CVE-2026-20841)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Feb 16, 20264mo ago

Munge vulnerability fixed after roughly 20 years

A long-standing Munge vulnerability, tracked as CVE-2026-25506, was finally fixed after existing for about two decades. The recap highlights the remediation as a notable legacy-security milestone.

Apple patches dyld zero-day used in targeted attacks

Apple disclosed and fixed CVE-2026-20700, a dyld memory corruption zero-day reportedly used in sophisticated targeted attacks. The patch marked a significant response to active exploitation.

Chrome zero-day CVE-2026-2441 is disclosed and patched

Google disclosed and patched CVE-2026-2441, a Chrome use-after-free vulnerability reported as actively exploited. The fix was included among the week's major browser and platform security updates.

Microsoft removes hijacked AgreeTo add-in from its store

After the Outlook add-in hijack was identified, Microsoft removed the AgreeTo add-in from the Microsoft store. This was the vendor response to the credential-theft campaign tied to the add-in.

Attackers exploit abandoned Outlook add-in domain to steal 4,000+ credentials

A previously legitimate Outlook add-in called AgreeTo was repurposed into a phishing kit after attackers took over an abandoned associated domain. The campaign resulted in theft of more than 4,000 Microsoft account credentials.

Feb 12, 20264mo ago

Law enforcement action targets $73.6 million pig-butchering scam

Authorities took action against a pig-butchering fraud operation involving $73.6 million in losses. The bulletin cites the case as a notable law-enforcement development during the reporting period.

Global Telnet traffic drops ahead of GNU InetUtils telnetd auth-bypass disclosure

Researchers observed an anomalous global collapse in Telnet traffic that may indicate pre-disclosure mitigation activity related to CVE-2026-24061, a critical GNU InetUtils telnetd authentication-bypass flaw. The traffic shift was noted as an unusual ecosystem signal around the vulnerability.

Quest Desktop Authority named-pipe flaw enables SYSTEM-level RCE

A major vulnerability in Quest Desktop Authority was disclosed involving a named-pipe issue that could allow SYSTEM-level remote code execution. The bulletin presents it as a significant newly revealed enterprise software risk.

Anthropic discloses unpatched zero-click Claude Desktop Extensions RCE risk

Researchers reported a zero-click remote code execution risk in Claude Desktop Extensions driven by prompt-injected Google Calendar events. Anthropic chose not to fix the issue, making the disclosure itself a notable development.

Microsoft patches Windows Notepad Markdown link RCE

Microsoft patched CVE-2026-20841, a command-injection flaw in Windows Notepad that could allow remote code execution through malicious Markdown links. The issue was highlighted as a newly patched exposure in the February threat roundup.

Dec 31, 20256mo ago

Google patches Looker RCE and authorization-bypass chain

Google patched a vulnerability chain in Looker tracked as CVE-2025-12743 that could enable remote code execution and authorization bypass. The bulletin cites this as a major disclosed and remediated enterprise software issue.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

153 LINKEDOpen in app
Affected products
33 linked
Google DriveGoogle DriveTvosVisionosIpadosWatchos1passwordGoogle DocsIosMacos TahoeMicrosoft OfficeIosTelegramWhatsappWindows 117-ZipCloudflareDiscordTiktokWordpressMysqlWindows NotepadNodejsWindowsBingOnedriveDropboxMysqlKubernetes7-ZipDropboxNodejsNodejs
Organizations
70 linked
Microsoft CorporationGoogleGreyNoiseZscalerTrend MicroChainalysisCTM360BeyondtrustKoi SecurityLexfoThe Walt Disney CompanyPalo Alto NetworksS2W1passwordAppleReutersCloudSEKFlareOntinueAmazon Web ServicesDiscordMalwarebytesTeslaTenableCloudflareHalcyonDropboxSupabaseLayerXCYFIRMATeamt5TelegramSimpleHelpSilent PushCyderesArs TechnicaMiggo SecurityJozeal Network Technology Co., Limitedk-IDLVCHA VPNSmiao IntelligenceNet Monitor for EmployeesCheck Point Software TechnologiesChargepointQuest SoftwareCisco SystemsCybleBinary DefenseForcepointBritish TelecomGuidePointCato NetworksAnthropicCofenseCox CommunicationsCharter CommunicationsVultrNetskopeGuidePoint SecurityConnectwiseHuntressBitdefenderNetSPINetlifyAlpitronicCheck Point Software Technologies Ltd.Fuzzware.ioForbes RussiaBritish Telecommunications plcGreyNoise Intelligence, Inc.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.