What happened
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel ยท 404godd/CVE-2026-20841-PoC๐ Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.RCEHIGHAnalyzedโ
0โ 0EPSS 11.65%CVE data: CNAUpdated 26 Aug 2026Tags: agent, chinese, cv, cve-2016-0856, cve-2026-20841, deep-learning, ethereum, hacktoberfest404godd2026-02-26CandidateCVE-Intel ยท hamzamalik3461/CVE-2026-20841๐ Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.RCEHIGHAnalyzedโ
1โ 2EPSS 11.65%CVE data: CNAUpdated 26 Aug 2026Tags: agent, command-injection, cv, cve, cve-2016-0856, cve-2026-20841, ethereum, exploithamzamalik34612024-09-22CandidateCVE-Intel ยท BTtea/CVE-2026-20841-PoCPoCPoCHIGHAnalyzedโ
141โ 21EPSS 11.65%CVE data: CNAUpdated 23 Aug 2026BTtea2026-02-11CandidateCVE-Intel ยท uky007/CVE-2026-20841_notepad_analysisExploitPythonHIGHAnalyzedโ
3โ 1EPSS 11.65%CVE data: CNACode indexedUpdated 20 Aug 2026uky0072026-02-12CandidateCVE-Intel ยท 0xBlackash/CVE-2026-20841CVE-2026-20841ExploitJavaScriptHIGHAnalyzedโ
1โ 1EPSS 11.65%CVE data: CNACode indexedUpdated 3 Jun 20260xBlackash2026-06-01CandidateCVE-Intel ยท whiskeylab/notepad_CVE_2026_20841Notepad CVE-2026-20841ExploitHIGHAnalyzedโ
0โ 0EPSS 11.65%CVE data: CNAUpdated 7 Apr 2026whiskeylab2026-04-07CandidateCVE-Intel ยท atiilla/CVE-2026-20841ExploitPythonHIGHAnalyzedโ
5โ 4EPSS 11.65%CVE data: CNACode indexedUpdated 12 Mar 2026atiilla2026-02-12CandidateCVE-Intel ยท tangent65536/CVE-2026-20841PoC for the "Windows Notepad RCE"RCEPythonHIGHAnalyzedโ
2โ 1EPSS 11.65%CVE data: CNACode indexedUpdated 28 Feb 2026tangent655362026-02-11CandidateSource timeline
Discovered through CVE-IntelView source โ
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.