Junglewise Threat Intelligence

CVE-2026-21513: Microsoft MSHTML Framework protection mechanism failure

CVE-2026-21513 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2026-02-10

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft MSHTML Framework, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows Server 2012, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security flaw has been identified in the Microsoft MSHTML Framework, a core component used by Windows to render web content and documents. This vulnerability allows an attacker to bypass built-in security protections, potentially leading to unauthorized access or the execution of malicious code if a user visits a compromised website or opens a malicious file. This issue is actively being exploited in the wild, posing a significant risk to corporate data and system integrity.

Technical details

A protection mechanism failure (CWE-693) exists in the Microsoft MSHTML Framework. The vulnerability allows a remote, unauthenticated attacker to bypass security features by convincing a user to interact with malicious content, such as a specially crafted website or document. The attack vector is network-based with low complexity, though it requires user interaction (UI:R). Successful exploitation can result in high impacts on confidentiality, integrity, and availability. This vulnerability is confirmed to be exploited in the wild and is tracked in the CISA Known Exploited Vulnerabilities (KEV) catalog. Microsoft has released updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.14393.8868, 10.0.17763.8389, 10.0.19045.6937, 10.0.19044.6937
  • Microsoft Windows 11 up to (excluding) 10.0.26100.7781, 10.0.22631.6649, 10.0.26200.7781
  • Microsoft Windows Server 2012 R2 and base versions
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.8868
  • Microsoft Windows Server 2019
  • Microsoft MSHTML Framework

Timeline

  • 2026-02-10: disclosed
  • 2026-02-10: advisory
  • 2026-02-10: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2026-02-10: exploited

Related threats