Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
- Vendor
- Microsoft
- Product
- MSHTML Framework (Windows)
- CVSS
- 8.8
- EPSS (exploit probability)
- 15.4%
- Status
- kev
- Published
A protection mechanism failure in Microsoft’s MSHTML Framework allows an unauthenticated remote attacker to bypass a security feature over a network. NVD rates it CVSS 8.8 (high). Microsoft patched it in the February 2026 Patch Tuesday cycle.
The vulnerability surfaced in operational context when Rapid7 analyzed an exposed attacker WebDAV lab in July 2026. Among the artifacts recovered: CVE-2026-21513 was one of three already-patched CVEs the operator was systematically QA’ing against targets in phishing campaigns targeting Mexico — alongside CVE-2025-33053 and CVE-2025-24054. The lab exposure confirmed active attacker interest in this flaw months after Microsoft shipped the fix.
Patch: apply the February 2026 Patch Tuesday cumulative update for your Windows version. NVD record.
