{"id":1633,"date":"2026-02-13T19:26:26","date_gmt":"2026-02-13T19:26:26","guid":{"rendered":"https:\/\/softstations.com\/?p=1633"},"modified":"2026-02-13T19:26:26","modified_gmt":"2026-02-13T19:26:26","slug":"microsoft-fixes-critical-windows-11-notepad-vulnerability-update-now","status":"publish","type":"post","link":"https:\/\/softstations.com\/microsoft-fixes-critical-windows-11-notepad-vulnerability-update-now\/","title":{"rendered":"Microsoft Fixes Critical Windows 11 Notepad Vulnerability \u2013 Update Now"},"content":{"rendered":"<p>Microsoft has released an important security update for Windows 11 that fixes a dangerous flaw in the built-in Notepad app, a vulnerability that could have let attackers run malicious code on affected PCs.<\/p>\n<h3 data-start=\"443\" data-end=\"460\">What Happened<\/h3>\n<p data-start=\"462\" data-end=\"880\">The flaw, tracked as <strong data-start=\"483\" data-end=\"501\">CVE-2026-20841<\/strong>, allowed a specially crafted Markdown (.md) file to trigger remote code execution if a user opened the file in Notepad and clicked a malicious link. Because Notepad had added support for Markdown links in recent updates, attackers could embed harmful links that launch remote files or programs if clicked \u2014 without a clear security warning.<\/p>\n<p data-start=\"882\" data-end=\"1283\">Remote code execution bugs are among the <em data-start=\"923\" data-end=\"933\">riskiest<\/em> types of software vulnerabilities because they can let hackers install malware, steal data, or take control of a system with the same permissions as the signed-in user. Notepad\u2019s ubiquity on Windows makes it an attractive target for social engineering attacks, such as email attachments or project README files.<\/p>\n<h3 data-start=\"1285\" data-end=\"1311\">How Microsoft Fixed It<\/h3>\n<p data-start=\"1313\" data-end=\"1618\">The issue was addressed as part of the <strong data-start=\"1352\" data-end=\"1383\">February 2026 Patch Tuesday<\/strong> updates distributed through Windows Update. The update changes how Notepad handles links in Markdown files \u2014 now requiring a clear prompt before launching content that uses non-standard protocols.<\/p>\n<p data-start=\"1620\" data-end=\"1894\">This means that when a user tries to open links using protocols like <code data-start=\"1689\" data-end=\"1698\">file:\/\/<\/code>, <code data-start=\"1700\" data-end=\"1720\">ms-appinstaller:\/\/<\/code>, or similar, Notepad will first display a warning asking for permission, reducing the risk of attackers executing code without notice.<\/p>\n<h3 data-start=\"1896\" data-end=\"1920\">What Users Should Do<\/h3>\n<p data-start=\"1922\" data-end=\"2185\">Windows 11 users are strongly advised to install the latest updates as soon as they\u2019re available. Because Notepad updates can also be delivered through the Microsoft Store, most systems should receive the patch automatically.<\/p>\n<p data-start=\"2187\" data-end=\"2394\">Until the patch is applied, users should be cautious about opening Markdown files from unknown or untrusted sources and avoid clicking suspicious links inside documents.<\/p>\n<p data-start=\"2187\" data-end=\"2394\">\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has released an important security update for Windows 11 that fixes a dangerous flaw in the built-in Notepad app, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1634,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_rishi_post_view_count":328,"multiple_authors":[],"quick_summary":"","sticky_promo_single":[]},"categories":[28],"tags":[],"class_list":["post-1633","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","rishi-post"],"rishi__cb_customizer_meta":"","comments_count":"0","_links":{"self":[{"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/posts\/1633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/comments?post=1633"}],"version-history":[{"count":1,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/posts\/1633\/revisions"}],"predecessor-version":[{"id":1635,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/posts\/1633\/revisions\/1635"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/media\/1634"}],"wp:attachment":[{"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/media?parent=1633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/categories?post=1633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/softstations.com\/wp-json\/wp\/v2\/tags?post=1633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}