CVE-2026-20841
HIGH 7.8EPSS 11.7%
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 11.65% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2026-02-10
- Updated
- 2026-08-19
Proof-of-concept exploits (14)
- hamzamalik3461/CVE-2026-208411★ · 2026-08-29
- BTtea/CVE-2026-20841-PoC141★ · 2026-02-11
- atiilla/CVE-2026-208415★ · 2026-02-12
- patchpoint/CVE-2026-2084112★ · 2026-02-12
- dogukankurnaz/CVE-2026-20841-PoC2★ · 2026-02-12
- tangent65536/CVE-2026-208412★ · 2026-02-11
- RajaUzairAbdullah/CVE-2026-208410★ · 2026-02-11
- SecureWithUmer/CVE-2026-208411★ · 2026-02-12
- 404godd/CVE-2026-20841-PoC0★ · 2026-08-30
- EleniChristopoulou/PoC-CVE-2026-208410★ · 2026-02-17
- hackfaiz/CVE-2026-20841-PoC1★ · 2026-02-12
- 0xBlackash/CVE-2026-208411★ · 2026-06-02
- whiskeylab/notepad_CVE_2026_20841
- heaker12/CVE-POC