CVE-2026-20841
Published Feb 10, 2026Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
- evidence mentions
- 8
- Buzz score
- 44.0
Vendor/product archive
1 CVEs tagged to microsoft / windows_notepad — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.