Security Update Guide - Microsoft Security Response Center

Zero Day Initiative — CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

In this excerpt of a TrendAI Research Services vulnerability report, Nikolai Skliarenko and Yazhi Wang of the TrendAI Research team detail a recently patched command injection vulnerability in the Windows Notepad application. This bug was originally discovered by Cristian Papa and Alasdair Gorniak

Zero Day Initiative
@timb_machine Cool writeup, but boy it's hard to take "TrendAI"seriously
@timb_machine I…wait…Is the "vulnerability" the fact that Markdown files can contain links? Because that's what it looks like to me.