CVE-2026-21513
KEVmass1MSHTML Security Feature Bypass in Windows Exploited in the Wild (CVE-2026-21513)
CISA: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
CVE-2026-21513 is a protection mechanism failure (CWE-693) in Microsoft's MSHTML framework, the legacy HTML rendering engine built into Windows and hosted by browsers, Office, and countless applications that display web content. An unauthorized attacker can exploit it over a network to bypass a Windows security feature; the CVSS vector requires user interaction (UI:R), consistent with delivery via a malicious link or document whose content is rendered through MSHTML. Although classified as a security-feature bypass, the vendor-scored impact is high for confidentiality, integrity, and availability (C:H/I:H/A:H), indicating significant downstream effect when chained with other techniques. All supported Windows client and server releases are in scope, from Windows 10 1607 through Windows 11 25H2 and Windows Server 2012 through Windows Server 2022 23H2. The flaw is being actively exploited: CISA added it to the KEV catalog on 2026-02-10, Microsoft confirmed in-the-wild exploitation, and public reporting ties exploitation to APT28 ahead of the February 2026 Patch Tuesday; EPSS assigns a 15.6% probability of exploitation within 30 days (97th percentile).
What to do: Apply Microsoft's February 2026 Windows security updates to all in-scope Windows 10, Windows 11, and Windows Server versions as soon as possible; the flaw is KEV-listed and confirmed exploited in the wild (reporting ties it to APT28), making patching a priority even though ransomware use is not yet confirmed. Because the vector requires user interaction and MSHTML is reached through rendered content, strengthen email and web-lure defenses and hunt for APT28 activity on unpatched hosts; US federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use if mitigations are unavailable.
| Microsoft Windows 10 | 1607 |
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 21H2 |
| Microsoft Windows 10 | 22H2 |
| Microsoft Windows 11 | 23H2 |
| Microsoft Windows 11 | 24H2 |
| Microsoft Windows 11 | 25H2 |
| Microsoft Windows Server 2012 | 2012 (as listed in CPE) |
| Microsoft Windows Server 2016 | 2016 (as listed in CPE) |
| Microsoft Windows Server 2019 | 2019 (as listed in CPE) |
| Microsoft Windows Server 2022 | 2022 (as listed in CPE) |
| Microsoft Windows Server 2022 | 2022 23H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H