Skip to main content

CVE detail

CVE-2026-20841

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

CVSS 7.8 · HighBuzz score 44.01 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 44.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 5.5
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
16.5
4 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
5.5
1 repos · best confidence 0.99
Best PoC traction
1
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • Added FAQ information. This is an informational change only.

    vendormsrc.microsoft.comMay 11, 2026, 2:00 PM
  • bitrary commands in the security context of the victim's account. The following is a portion of their write-up covering CVE-2026-20841, with a few minimal modifications. A remote code execution vulnerability has been reported in Microsoft Windows Notepad. The vulnerability is due to improper validation of links in Markdown files. A remote attacker coul

    vendorwww.thezdi.comFeb 19, 2026, 9:24 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as much as prevention, and how the airline manages risk across an interconnected ecosystem of vendors, partners, and infrastructure providers. What … More →

    newswww.helpnetsecurity.comFeb 15, 2026, 9:00 AM
  • Among the many security fixes released by Microsoft on February 2026 Patch Tuesday is one for CVE-2026-20841, a command injection vulnerability in Notepad that could be exploited by attackers to achieve remote code execution on targets’ Windows system. About CVE-2026-20841 For many, many years, Windows Notepad was a simple text editor and a staple tool for everyone who wanted a no-frills way to work with plain text, but in early 2022, Microsoft started redesigning it … More →

    newswww.helpnetsecurity.comFeb 12, 2026, 2:47 PM
  • Linked URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 | Posted by rolisz | 5 points | 1 comments

    communitynews.ycombinator.comFeb 11, 2026, 8:35 AM
  • Linked URL: https://www.cve.org/CVERecord?id=CVE-2026-20841 | Posted by riffraff | 804 points | 515 comments

    communitynews.ycombinator.comFeb 11, 2026, 6:15 AM
  • Linked URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841 | Posted by dunder_cat | 23 points | 4 comments

    communitynews.ycombinator.comFeb 10, 2026, 11:18 PM
  • The February 2026 Security Update ReviewZero Day Initiative

    ake a closer look at some of the more interesting updates for this month, starting with the bugs under active attack: - CVE-2026-21510 - Windows Shell Security Feature Bypass Vulnerability This bug is listed as a security feature bypass, but it could also be classified as code execution. An attacker can bypass Windows SmartScreen and Windows Shell secu

    vendorwww.thezdi.comFeb 10, 2026, 6:30 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 1 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-16763

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration…

    CVSS 1.9 · Low
    6 mentions
  • CVE-2024-58354

    cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_ta…

    CVSS 8.5 · High
    3 mentions
  • CVE-2026-47670

    DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute…

    CVSS 9.4 · Critical
    Public PoC observed2 mentions
  • CVE-2026-16735

    A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Change…

    CVSS 1.9 · Low
    6 mentions
  • CVE-2026-16733

    A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handl…

    CVSS 1.9 · Low
    6 mentions
  • CVE-2026-16631

    A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. Th…

    CVSS 1.9 · Low
    8 mentions