ZeroHour

CVE-2026-21513

KEVmass1

MSHTML Security Feature Bypass in Windows Exploited in the Wild (CVE-2026-21513)

CISA: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

CVSS 3.1
8.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2026-21513 is a protection mechanism failure (CWE-693) in Microsoft's MSHTML framework, the legacy HTML rendering engine built into Windows and hosted by browsers, Office, and countless applications that display web content. An unauthorized attacker can exploit it over a network to bypass a Windows security feature; the CVSS vector requires user interaction (UI:R), consistent with delivery via a malicious link or document whose content is rendered through MSHTML. Although classified as a security-feature bypass, the vendor-scored impact is high for confidentiality, integrity, and availability (C:H/I:H/A:H), indicating significant downstream effect when chained with other techniques. All supported Windows client and server releases are in scope, from Windows 10 1607 through Windows 11 25H2 and Windows Server 2012 through Windows Server 2022 23H2. The flaw is being actively exploited: CISA added it to the KEV catalog on 2026-02-10, Microsoft confirmed in-the-wild exploitation, and public reporting ties exploitation to APT28 ahead of the February 2026 Patch Tuesday; EPSS assigns a 15.6% probability of exploitation within 30 days (97th percentile).

What to do: Apply Microsoft's February 2026 Windows security updates to all in-scope Windows 10, Windows 11, and Windows Server versions as soon as possible; the flaw is KEV-listed and confirmed exploited in the wild (reporting ties it to APT28), making patching a priority even though ransomware use is not yet confirmed. Because the vector requires user interaction and MSHTML is reached through rendered content, strengthen email and web-lure defenses and hunt for APT28 activity on unpatched hosts; US federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use if mitigations are unavailable.

Affected
Microsoft Windows 101607
Microsoft Windows 101809
Microsoft Windows 1021H2
Microsoft Windows 1022H2
Microsoft Windows 1123H2
Microsoft Windows 1124H2
Microsoft Windows 1125H2
Microsoft Windows Server 20122012 (as listed in CPE)
Microsoft Windows Server 20162016 (as listed in CPE)
Microsoft Windows Server 20192019 (as listed in CPE)
Microsoft Windows Server 20222022 (as listed in CPE)
Microsoft Windows Server 20222022 23H2
Estimated exposure
masshundreds of millions of Windows devices and servers (effectively the entire supported Windows install base, >1 billion devices worldwide) — Windows runs on well over a billion devices globally and the CPE data lists every supported Windows 10/11 client release plus Windows Server 2012 through 2022 23H2, so nearly all consumer and enterprise Windows estates are in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news