Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogendpoint-software-vulnerabilitywidely-deployed-product-advisory

Actively Exploited Microsoft MSHTML Framework Zero-Day (CVE-2026-21513)

Updated 2mo agoFirst seen Feb 11, 20263 sources

Microsoft issued an urgent fix for an actively exploited MSHTML (Trident) security feature bypass tracked as CVE-2026-21513 (CVSS 8.8), which allows attackers to circumvent Windows security prompts and protections without requiring elevated privileges. Reported exploitation relies on social engineering to get a user to open specially crafted content—such as malicious HTML or shortcut (.lnk) files—delivered via email attachments, links, or downloads; the weakness is described as a protection mechanism failure (CWE-693) in how Windows Shell and MSHTML handle embedded content and validation.

CISA added CVE-2026-21513 to the Known Exploited Vulnerabilities (KEV) catalog with required action to apply vendor mitigations/patches per Microsoft guidance and a remediation due date of 2026-03-03, reinforcing that exploitation is occurring and prioritization is warranted. Separate reporting also described other Microsoft zero-days patched in the same timeframe—Microsoft Word OLE mitigation bypass (CVE-2026-21514) and a Windows Desktop Window Manager (dwm.exe) privilege escalation (CVE-2026-21519)—but those are distinct vulnerabilities and not part of the MSHTML-specific KEV entry.

Share:
Actively Exploited Microsoft MSHTML Framework Zero-Day (CVE-2026-21513)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 10, 20264mo ago

CISA adds CVE-2026-21513 to the KEV catalog

CISA added CVE-2026-21513 to its Known Exploited Vulnerabilities catalog, confirming federal agencies should prioritize remediation. The KEV entry set a remediation deadline of March 3, 2026 and directed organizations to apply Microsoft's mitigations.

Microsoft releases Patch Tuesday fix for CVE-2026-21513

On February 10, 2026, Microsoft shipped security updates addressing CVE-2026-21513 for supported Windows versions including Windows 10, Windows 11, and multiple Windows Server editions. The patch remediated the MSHTML/Windows Shell handling issue that could enable execution without proper security validation.

Microsoft discloses CVE-2026-21513 as an exploited MSHTML zero-day

Microsoft identified CVE-2026-21513 in the MSHTML (Trident) framework as a security feature bypass vulnerability and stated it had been publicly disclosed and actively exploited in the wild before a fix was available. The flaw could let attackers bypass Windows execution prompts by luring users into opening crafted HTML or malicious shortcut files.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.