---
title: "Microsoft Added AI to Notepad and It Created a Security Failure Because the AI Was Stupidly Easy for Hackers to Trick"
description: "As Microsoft continues to force AI features onto users of its Windows operating system and other crucial software, glaring issues keep cropping up. Executives have promised to turn the platform into an \"[agentic OS]()\" to the dismay of many users,&hellip;"
date: "2026-02-14"
modified: "2026-02-14"
authors:
  - name: "Victor Tangermann"
    job_title: "Senior Editor"
    link: "https://futurism.com/authors/victor"
url: "https://futurism.com/artificial-intelligence/microsoft-added-ai-notepad-security-flaw"
categories:
  - "Artificial Intelligence"
---

# Microsoft Added AI to Notepad and It Created a Security Failure Because the AI Was Stupidly Easy for Hackers to Trick

![Malware researchers found a serious security vulnerability plaguing Microsoft's latest AI-enhanced version of its plain-text editor, Notepad.](<https://futurism.com/wp-content/uploads/2026/02/microsoft-added-ai-notepad-security-flaw.jpg>)
*Futurism*

As Microsoft continues to force AI features onto users of its Windows operating system and other crucial software, glaring issues keep cropping up. Executives have promised to turn the platform into an "[agentic OS](<https://futurism.com/artificial-intelligence/windows-users-furious-microsoft-agentic-os>)" to the dismay of many users, with CEO Satya Nadella boasting that much of the company's [code is now being written by AI](<https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-as-30percent-of-microsoft-code-is-written-by-ai.html>) — while [condemning those](<https://futurism.com/artificial-intelligence/microsoft-satya-nadella-ai-slop>) who use the newly-minted pejorative "Microslop."

While new bugs in an operating system software update are certainly commonplace, some have noticed that the problem is [getting worse](<https://www.theverge.com/news/864032/microsofts-out-of-band-windows-11-update-bug>) than usual these days. Just last month, some Windows 11 enterprise users [were aggravated](<https://futurism.com/artificial-intelligence/microsoft-update-prevent-shutdown>) after finding that their systems were stuck in an endless shutdown loop, a [security risk](<https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3764msgdesc>) if left unattended.

Even the company's Notepad app, which once allowed users to jot down notes in plain text, has turned into a bloated, AI-enhanced security liability. As malware researchers from the collective [vx-underground found](<https://x.com/vxunderground/status/2021355936691204115?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2021355936691204115%7Ctwgr%5E6237990106673a0e68b4ab9705bc25c886488e92%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcybernews.com%2Fsecurity%2Fwindows-notepad-vulnerable-to-remote-attacks-feature-creep-blamed%2F>), the app has a "remote code execution zero-day" — meaning a vulnerability in software unknown even to its creators.

According to [Microsoft documentation of the bug](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841>), "improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network."

"An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files," the documentation reads. (Markdown is a language for formatting text.)

While the bug was patched in Microsoft's monthly security updates, it's yet another instance of a tech company pushing AI features on its customers against their will — with potentially disastrous results. Case in point, Microsoft's AI "Recall" feature, which was designed to quietly take screenshots of users' screens every few seconds, turned out to be an enormous security nightmare in late 2024, forcing the Windows team to go back to the drawing board. While it was pushed to users in mid-2025, experts continue to warn that it's a [privacy nightmare](<https://www.youtube.com/watch?v=j0pXFwCkF-k>) and [far too risky to be used](<https://www.youtube.com/watch?v=uk2Xy92vzFg>).

The latest Notepad bug is symptomatic of a much larger struggle for the tech giant. Last week, the *Wall Street Journal* [published an investigation](<https://www.wsj.com/tech/ai/microsofts-pivotal-ai-product-is-running-into-big-problems-ce235b28>), quoting current and former employees, who found that Microsoft's confusing branding and grating lack of cohesion between its AI products had [frustrated and turned off users](<https://futurism.com/artificial-intelligence/microsoft-ai-efforts-faceplanting>). Worse yet, the adoption rate of its Copilot AI chatbot, which was baked into Windows 11, is extremely slim, suggesting a significant lack of public enthusiasm for the flagship feature.

To vx-underground, the latest Notepad vulnerability is a gross example of mission creep for an app that once served a far simpler function.

"Hot take: text editors don't need network functionality," the collective argued in a [tweet](<https://x.com/vxunderground/status/2021355936691204115?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2021355936691204115%7Ctwgr%5E6237990106673a0e68b4ab9705bc25c886488e92%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcybernews.com%2Fsecurity%2Fwindows-notepad-vulnerable-to-remote-attacks-feature-creep-blamed%2F>).

Others tended to agree with that assessment.

"Notepad \[remote code execution\] in 2026?" the account for digital security firm Secure.com [replied](<https://x.com/Securedotcom/status/2021498345441853797?s=20>). "We really out here weaponizing the .txt file because we just HAD to have AI in our basic editor."

"If ur text editor has enough network functionality to trigger a remote shell, ur basically building a playground for attackers," the account added.

Some lamented the end of a far simpler, basic text-editing tool.

"Microsoft is turning Notepad into a slow, feature-heavy mess we don't need," Polytechnic University of Catalonia computer engineer Manel Rodero [tweeted](<https://x.com/manelrodero/status/2021493114771472646>), appending a screenshot of the documented vulnerability. "We just want something to open text files, not an AI-powered editor with security holes like this."

"Who the hell is in charge of this development?" he added.

"Obviously, an issue like this puts polarizing features under a microscope, and I totally get the innovation pursuit, but this feels like a prime example of a solution in search of a problem," IT systems engineer Nathan Kasco [responded](<https://x.com/Bu5yGiraffe/status/2021642169300259171>).

Rodero [argued](<https://x.com/manelrodero/status/2021661939332788240>) that Windows had plenty of areas that "need real improvement, but "instead, we keep getting visual tweaks and AI gimmicks that most users will never touch."

Microsoft has struggled to convince many of its customers of the benefits of AI in its latest operating system, with [hundreds of millions of **users**](<https://futurism.com/artificial-intelligence/windows-users-refusing-upgrade-windows-11-ai>) refusing to upgrade from Windows 10, as of late last year.

Many of the AI features that have been introduced leave plenty to be desired. Last month, programmer Ryan Fleury demonstrated that Windows 11's AI-powered search bar struggled with the very basics, leading to plenty of other netizens calling the company "Microslop."

Meanwhile, system administrators are forced to clean up after the company, making a mess of its core product.

"All this does is make system admins spend countless hours stripping out nonsense just to deploy a clean, well‑configured machine," Rodero [lamented](<https://x.com/manelrodero/status/2021662003417559267>).

**More on Windows and AI:** [*As Microsoft Stuffs Windows With AI, New Update Prevents Users From Turning Off Their PCs*](<https://futurism.com/artificial-intelligence/microsoft-update-prevent-shutdown>)

## Author
I've been at Futurism since 2017, where my role has evolved to encompass design, writing, and increasingly editing. I've always been fascinated by space exploration and advanced transportation, which I've leaned into by interviewing luminaries in those fields while closely following the dimensions of policy and regulation that allow next-generation projects to succeed -- or, sometimes, to fail. I'm also keenly interested in the effects of generative AI on society, policies, and democratic institutions, as well as clean energy, physics and biology, and the vagaries of tech leadership. My work for Futurism has been cited by publications including Ars Technica, Gizmodo, PC Magazine, Jalopnik, Fox News, and the New York Post. I spent my childhood living in locations including Manila, the Philippines, and Geneva, Switzerland, attended McGill University, and now live in Toronto, Canada. Before Futurism I worked at AskMen and a small photography studio. In my free time, I'm an avid gardener, foodie, and craft beer lover, as well as a maker of artisanal hot pepper sauces. I have a magnificent dog named Freida.

### Author social links  
[Bluesky](<https://bsky.app/profile/vtanger.bsky.social>)