Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitystate-sponsored-espionagewidely-deployed-product-advisoryendpoint-software-vulnerability

Exploitation of MSHTML Security Feature Bypass Patched in Microsoft February Update

Updated 3mo agoFirst seen Mar 4, 20263 sources

Microsoft’s February 2026 security update addressed 59 vulnerabilities across Windows, Azure, Microsoft Office, and Visual Studio Code, including 5 Critical issues. NSFOCUS reported that six vulnerabilities were already being exploited in the wild, including MSHTML Framework Security Feature Bypass (CVE-2026-21513), Windows Shell Security Feature Bypass (CVE-2026-21510), Microsoft Word Security Feature Bypass (CVE-2026-21514), Desktop Window Manager EoP (CVE-2026-21519), Windows Remote Access Connection Manager DoS (CVE-2026-21525), and Windows Remote Desktop Service EoP (CVE-2026-21533).

Akamai attributed active exploitation of CVE-2026-21513 to APT28, reporting the flaw affects all supported Windows versions and enables a security feature bypass leading to arbitrary file execution (CVSS 8.8). Akamai’s root-cause analysis placed the issue in ieframe.dll, in the _AttemptShellExecuteForHlinkNavigate hyperlink-navigation path, where insufficient URL validation can allow attacker-controlled input to reach code paths invoking ShellExecuteExW, enabling execution outside the intended browser security context. Akamai also linked a malicious sample (reported as document.doc.LnK.download) to APT28-associated infrastructure and described use of a crafted .lnk that embeds an HTML file and contacts wellnesscaremed[.]com as part of the exploitation chain prior to Microsoft’s February patch release.

Share:
Exploitation of MSHTML Security Feature Bypass Patched in Microsoft February Update
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 4, 20264mo ago

NSFOCUS issues advisory urging prioritization of February exploited CVEs

NSFOCUS CERT published an advisory summarizing Microsoft's February 2026 security updates and highlighted CVE-2026-21513 as one of the in-the-wild exploited vulnerabilities requiring urgent attention. The notice recommended prompt patching and verification of update installation across affected Microsoft products.

Mar 2, 20264mo ago

Akamai publishes technical analysis attributing CVE-2026-21513 to APT28

Akamai researchers disclosed technical details of CVE-2026-21513 exploitation, including the root cause in ieframe.dll, the use of nested iframes and multiple DOM contexts, and the bypass of Mark of the Web and Internet Explorer Enhanced Security Configuration. The analysis also described use of PatchDiff-AI and correlation with a malicious sample on VirusTotal tied to APT28 infrastructure.

Feb 11, 20264mo ago

CISA adds six February zero-days to KEV catalog

On 2026-02-11, CISA added the six actively exploited vulnerabilities addressed in Microsoft's February Patch Tuesday updates, including CVE-2026-21513, to its Known Exploited Vulnerabilities catalog. The agency ordered Federal Civilian Executive Branch agencies to remediate the flaws by 2026-03-03.

Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days

Microsoft releases February 2026 Patch Tuesday fixes for CVE-2026-21513

On 2026-02-11, Microsoft released its February security updates, patching 59 vulnerabilities across multiple products, including the MSHTML security feature bypass CVE-2026-21513. Microsoft reported CVE-2026-21513 among six vulnerabilities already exploited in the wild and updated hyperlink protocol validation to prevent unsafe execution outside the browser context.

APT28 exploits MSHTML zero-day CVE-2026-21513 in the wild

A zero-day in Microsoft's MSHTML framework, CVE-2026-21513, was exploited before a patch was available. Akamai attributed the activity to the Russian state-sponsored group APT28, which used a crafted .lnk file and infrastructure including wellnesscaremed[.]com to trigger arbitrary file or code execution and bypass browser security boundaries.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

89 LINKEDOpen in app
Vulnerabilities
58 linked
Microsoft MSHTML Framework Security Feature BypassMicrosoft Edge for Android UI Misrepresentation Spoofing VulnerabilityWindows Remote Access Connection Manager NULL Pointer Dereference DoSMicrosoft Word OLE Security Feature BypassWindows Shell SmartScreen and Security Prompt Bypass via Malicious LNK/LinkDesktop Window Manager Type Confusion Local Privilege EscalationWindows Remote Desktop Services Elevation of PrivilegeWindows Hyper-V Remote Code Execution VulnerabilityAzure Function Information Disclosure VulnerabilityUntitledUntitledWindows Subsystem for Linux Race Condition Privilege EscalationUntitledRCE in Azure Local via improper certificate validation (CVE-2026-21228)Information disclosure in Azure IoT Explorer via unrestricted IP bindSpoofing via Deserialization of Untrusted Data in Microsoft OutlookLocal EoP in Windows HTTP.sys via untrusted pointer dereferenceWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCode injection RCE in Microsoft Defender for Linux (Defender for Endpoint Linux extension)Windows Storage Elevation of Privilege VulnerabilityWindows LDAP Null Pointer Dereference Denial of ServiceInformation Disclosure in Azure Compute Gallery / Microsoft ACI Confidential ContainersWindows Cluster Client Failover Use-After-Free Elevation of PrivilegeRCE via unsafe deserialization in Azure SDK (Azure SDK for Python)Heap-based Buffer Overflow in Windows Hyper-VTOCTOU race condition RCE in GitHub Copilot and Visual Studio CodeWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.NET System.Security.Cryptography.Cose spoofing / security feature bypassCommand Injection Privilege Escalation in GitHub Copilot and Visual StudioCommand Injection RCE in GitHub Copilot and Visual StudioCommand Injection in GitHub Copilot and Visual Studio Code mcp.json HandlingWindows Hyper-V Security Feature Bypass VulnerabilityRemote Code Execution in Windows Notepad App via Markdown Link HandlingWindows NTLM searchConnector-ms NTLM Response Disclosure / SpoofingWindows Subsystem for Linux Use-After-Free Privilege EscalationXSS in Azure HDInsights (network spoofing)Spoofing in Microsoft Exchange Server InterceptorSmtpAgentLocal privilege escalation via link following in Windows App for MacWindows Kernel Elevation of Privilege Race ConditionLocal information disclosure in Microsoft Office Excel (improper input validation)Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege in Windows Ancillary Function Driver for WinSockOut-of-bounds read information disclosure in Microsoft Office ExcelMailslot File System Elevation of Privilege VulnerabilityPrivilege Escalation in Windows Connected Devices Platform ServiceWindows Graphics Component Use-After-Free Privilege EscalationHeap-based Buffer Overflow in Microsoft Graphics ComponentWindows GDI+ Buffer Over-read Denial of Service VulnerabilityWindows HTTP.sys Elevation of Privilege VulnerabilityRCE in Microsoft Power BI via improper input validationWindows Kernel Heap-Based Buffer Overflow Privilege EscalationWindows Kernel Information Disclosure VulnerabilityCommand Injection in Azure Compute Gallery / Microsoft ACI Confidential ContainersMicrosoft Outlook Spoofing VulnerabilityWindows Kernel Heap-Based Buffer Overflow Privilege EscalationRemote Code Execution in Windows Hyper-VUntitledWindows Remote Access Connection Manager Elevation of Privilege
Threat actors
1 linked
Affected products
18 linked
Azure Devops ServerWindows ServerAzure FunctionsPower Bi Report ServerNetGithub CopilotAzure ArcVisual Studio CodeWindows Subsystem For LinuxPower BiMicrosoft OfficeAzure Front DoorMicrosoft Defender For EndpointAzure LocalAzure Iot ExplorerAzure HdinsightWindows NotepadMicrosoft Office Word
Organizations
12 linked
Microsoft CorporationNSFOCUSGitHubAkamai TechnologiesTenableVirustotalACROS SecurityAction1ImmersiveCrowdStrikeAppleGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.