Microsoft patched a Windows Notepad command-injection vulnerability, CVE-2026-20841 (CVSS 8.8), that can lead to remote code execution when a user opens a Markdown file in Notepad and clicks a crafted malicious link. The issue is described as improper neutralization of special elements used in a command, enabling an attacker to trigger execution of remote or local payloads in the security context of the logged-in user. Public proof-of-concept examples indicate the flaw can be exercised using Markdown file:// links pointing to executables (e.g., file://C:/windows/system32/cmd.exe) and other special URI handlers.
The reporting appears as part of a broader weekly “ThreatsDay” roundup that also references other, separate security stories (e.g., AI prompt injection/RCE themes and other malware/exploit items), but the concrete, actionable item consistently detailed is the Notepad Markdown-link RCE and its patch. A separate “Daily Cyber News” post discusses Microsoft releasing fixes for multiple exploited flaws across widely deployed products, but it does not specifically corroborate the Notepad CVE or the Markdown-link exploitation path described in the roundup, making it contextually related to Microsoft patching activity but not the same discrete vulnerability story.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
A long-standing Munge vulnerability, tracked as CVE-2026-25506, was finally fixed after existing for about two decades. The recap highlights the remediation as a notable legacy-security milestone.
Apple disclosed and fixed CVE-2026-20700, a dyld memory corruption zero-day reportedly used in sophisticated targeted attacks. The patch marked a significant response to active exploitation.
Google disclosed and patched CVE-2026-2441, a Chrome use-after-free vulnerability reported as actively exploited. The fix was included among the week's major browser and platform security updates.
After the Outlook add-in hijack was identified, Microsoft removed the AgreeTo add-in from the Microsoft store. This was the vendor response to the credential-theft campaign tied to the add-in.
A previously legitimate Outlook add-in called AgreeTo was repurposed into a phishing kit after attackers took over an abandoned associated domain. The campaign resulted in theft of more than 4,000 Microsoft account credentials.
Authorities took action against a pig-butchering fraud operation involving $73.6 million in losses. The bulletin cites the case as a notable law-enforcement development during the reporting period.
Researchers observed an anomalous global collapse in Telnet traffic that may indicate pre-disclosure mitigation activity related to CVE-2026-24061, a critical GNU InetUtils telnetd authentication-bypass flaw. The traffic shift was noted as an unusual ecosystem signal around the vulnerability.
A major vulnerability in Quest Desktop Authority was disclosed involving a named-pipe issue that could allow SYSTEM-level remote code execution. The bulletin presents it as a significant newly revealed enterprise software risk.
Researchers reported a zero-click remote code execution risk in Claude Desktop Extensions driven by prompt-injected Google Calendar events. Anthropic chose not to fix the issue, making the disclosure itself a notable development.
Microsoft patched CVE-2026-20841, a command-injection flaw in Windows Notepad that could allow remote code execution through malicious Markdown links. The issue was highlighted as a newly patched exposure in the February threat roundup.
Google patched a vulnerability chain in Looker tracked as CVE-2025-12743 that could enable remote code execution and authorization bypass. The bulletin cites this as a major disclosed and remediated enterprise software issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcethehackernews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.