
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that allows an unauthorized remote attacker to bypass a security feature over a network. It affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. Microsoft disclosed and patched the vulnerability on February 10, 2026, as part of its monthly Patch Tuesday release. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC, CISA KEV).
The vulnerability stems from a protection mechanism failure (CWE-693) in the MSHTML Framework — the legacy rendering engine embedded in Windows — which fails to properly enforce security prompts when processing specially crafted HTML files or .lnk shortcut files. Exploitation requires user interaction (e.g., opening a malicious file delivered via email or download), but requires no attacker privileges, making it accessible to a wide range of threat actors. Akamai published an in-depth exploit analysis detailing the in-the-wild exploitation mechanics, including how the flaw was used to silently bypass Windows security warnings and achieve code execution (Akamai Analysis, Microsoft MSRC).
Successful exploitation results in complete compromise of the affected system, with high impacts to confidentiality, integrity, and availability. Attackers can execute arbitrary code with the privileges of the targeted user, enabling credential theft, lateral movement within enterprise networks, data exfiltration, and deployment of additional malware payloads. APT28's use of this vulnerability in espionage campaigns targeting Ukraine and NATO allies demonstrates the potential for significant geopolitical and operational damage (Feedly Intelligence, The Hacker News).
CVE-2026-21513 was exploited as a zero-day in the wild prior to the February 10, 2026 patch, and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day as the patch release with a due date of March 3, 2026 (CISA KEV). Russia-linked APT28 (also known as Pawn Storm/Fancy Bear) has been attributed as the primary threat actor exploiting this vulnerability, using it in campaigns targeting Ukrainian defense supply chains and NATO allies, deploying the PRISMEX and GRUNT malware families (The Hacker News APT28, Trend Micro). No public proof-of-concept exploit code is known to exist independently, but the vulnerability has been weaponized in sophisticated nation-state operations. The EPSS score is approximately 0.0299 (2.99%), though active exploitation by a nation-state actor significantly elevates real-world risk.
.lnk shortcut files and deliver them to targets via email attachments or links to attacker-controlled download servers..lnk file or opening an HTML document), triggering MSHTML Framework processing..lnk files; NTLM authentication requests to external/untrusted hosts (indicative of credential harvesting)..lnk files or HTML files in user download/temp directories; PRISMEX or GRUNT malware artifacts on disk; newly created scheduled tasks or registry run keys for persistence.cmd.exe, powershell.exe, mshta.exe) spawned by explorer.exe or email client processes; SmartScreen bypass events in Windows Defender logs.mshtml.dll host processes launching scripting engines or network tools); steganography-related file access patterns noted in APT28 PRISMEX campaigns..lnk or .html attachments targeting defense, government, or NATO-affiliated personnel (Akamai Analysis, Trend Micro).Microsoft released patches on February 10, 2026 addressing CVE-2026-21513 across all affected Windows versions. Specific patched build numbers include: Windows 10 21H2/22H2 (10.0.19044/19045.6937), Windows 10 1809/Server 2019 (10.0.17763.8389), Windows 10 1607/Server 2016 (10.0.14393.8868), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313) (Microsoft MSRC). CISA mandated federal agencies apply patches by March 3, 2026 (CISA KEV). As interim mitigations, organizations should implement email filtering to block .lnk and suspicious HTML attachments, enforce user awareness training to avoid opening unsolicited files, and consider restricting execution of scripts and HTML files in email clients.
The vulnerability received significant attention from the security community as one of six actively exploited zero-days patched in Microsoft's February 2026 Patch Tuesday. Tenable's Satnam Narang highlighted it as a critical priority, and Akamai published a detailed exploit analysis blog post that was widely shared on Reddit's r/blueteamsec and r/SecOpsDaily communities (Tenable, Akamai Analysis). The subsequent attribution to APT28 in early March 2026 generated broad media coverage across The Hacker News, Security Affairs, SC World, and Forbes, with security researchers on social media emphasizing the geopolitical implications of Russian state-sponsored exploitation targeting NATO allies (The Hacker News APT28, Security Affairs). Trend Micro's subsequent PRISMEX campaign report further elevated community concern about the ongoing threat actor activity (Trend Micro).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."