CVE-2026-20841: exploitation status and patch state
CVE-2026-20841 · CVSS 7.8 HIGH · EPSS 12% · patch available
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
Is CVE-2026-20841 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 12%.
Public exploit code: none found in monitored sources.