Skip to content
feed: live
>_ 0dayNews
CVE Record
[ HIGH ] CVE-2026-21513

Microsoft MSHTML security feature bypass

Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.

cat cve-2026-21513.json
Vendor
Microsoft
Product
MSHTML Framework (Windows)
CVSS
8.8
EPSS (exploit probability)
15.4%
Status
kev
Published

A protection mechanism failure in Microsoft’s MSHTML Framework allows an unauthenticated remote attacker to bypass a security feature over a network. NVD rates it CVSS 8.8 (high). Microsoft patched it in the February 2026 Patch Tuesday cycle.

The vulnerability surfaced in operational context when Rapid7 analyzed an exposed attacker WebDAV lab in July 2026. Among the artifacts recovered: CVE-2026-21513 was one of three already-patched CVEs the operator was systematically QA’ing against targets in phishing campaigns targeting Mexico — alongside CVE-2025-33053 and CVE-2025-24054. The lab exposure confirmed active attacker interest in this flaw months after Microsoft shipped the fix.

Patch: apply the February 2026 Patch Tuesday cumulative update for your Windows version. NVD record.