CVE-2026-21513
vulnerability analysis and mitigation

Overview

CVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that allows an unauthorized remote attacker to bypass a security feature over a network. It affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. Microsoft disclosed and patched the vulnerability on February 10, 2026, as part of its monthly Patch Tuesday release. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC, CISA KEV).

Technical details

The vulnerability stems from a protection mechanism failure (CWE-693) in the MSHTML Framework — the legacy rendering engine embedded in Windows — which fails to properly enforce security prompts when processing specially crafted HTML files or .lnk shortcut files. Exploitation requires user interaction (e.g., opening a malicious file delivered via email or download), but requires no attacker privileges, making it accessible to a wide range of threat actors. Akamai published an in-depth exploit analysis detailing the in-the-wild exploitation mechanics, including how the flaw was used to silently bypass Windows security warnings and achieve code execution (Akamai Analysis, Microsoft MSRC).

Impact

Successful exploitation results in complete compromise of the affected system, with high impacts to confidentiality, integrity, and availability. Attackers can execute arbitrary code with the privileges of the targeted user, enabling credential theft, lateral movement within enterprise networks, data exfiltration, and deployment of additional malware payloads. APT28's use of this vulnerability in espionage campaigns targeting Ukraine and NATO allies demonstrates the potential for significant geopolitical and operational damage (Feedly Intelligence, The Hacker News).

Exploitability

CVE-2026-21513 was exploited as a zero-day in the wild prior to the February 10, 2026 patch, and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day as the patch release with a due date of March 3, 2026 (CISA KEV). Russia-linked APT28 (also known as Pawn Storm/Fancy Bear) has been attributed as the primary threat actor exploiting this vulnerability, using it in campaigns targeting Ukrainian defense supply chains and NATO allies, deploying the PRISMEX and GRUNT malware families (The Hacker News APT28, Trend Micro). No public proof-of-concept exploit code is known to exist independently, but the vulnerability has been weaponized in sophisticated nation-state operations. The EPSS score is approximately 0.0299 (2.99%), though active exploitation by a nation-state actor significantly elevates real-world risk.

Exploitation steps

  1. Reconnaissance: APT28 operators identify targets — government entities, defense contractors, and NATO-affiliated organizations — via spear-phishing email campaigns or watering hole attacks.
  2. Payload Delivery: Attackers craft malicious HTML files or .lnk shortcut files and deliver them to targets via email attachments or links to attacker-controlled download servers.
  3. User Interaction: The target user opens the malicious file (e.g., double-clicking a .lnk file or opening an HTML document), triggering MSHTML Framework processing.
  4. Security Bypass: The MSHTML protection mechanism failure causes Windows to skip or suppress the expected security warning/prompt (e.g., Mark-of-the-Web or SmartScreen checks), allowing the malicious content to execute without user confirmation.
  5. Code Execution: Arbitrary code runs in the context of the logged-in user, enabling the attacker to drop additional payloads such as PRISMEX or GRUNT malware.
  6. Post-Exploitation: The attacker establishes persistence, harvests credentials (including NTLM hashes), and moves laterally within the target network to achieve espionage objectives (Akamai Analysis, Trend Micro, SecPod).

Indicators of compromise

  • Network: Outbound connections from Windows systems to unknown or suspicious IP addresses following the opening of HTML or .lnk files; NTLM authentication requests to external/untrusted hosts (indicative of credential harvesting).
  • File System: Presence of unexpected .lnk files or HTML files in user download/temp directories; PRISMEX or GRUNT malware artifacts on disk; newly created scheduled tasks or registry run keys for persistence.
  • Logs: Windows Security event logs showing process creation events (e.g., cmd.exe, powershell.exe, mshta.exe) spawned by explorer.exe or email client processes; SmartScreen bypass events in Windows Defender logs.
  • Process Behavior: Unusual child processes spawned by MSHTML-related processes (e.g., mshtml.dll host processes launching scripting engines or network tools); steganography-related file access patterns noted in APT28 PRISMEX campaigns.
  • Email/Delivery: Spear-phishing emails with .lnk or .html attachments targeting defense, government, or NATO-affiliated personnel (Akamai Analysis, Trend Micro).

Mitigation and workarounds

Microsoft released patches on February 10, 2026 addressing CVE-2026-21513 across all affected Windows versions. Specific patched build numbers include: Windows 10 21H2/22H2 (10.0.19044/19045.6937), Windows 10 1809/Server 2019 (10.0.17763.8389), Windows 10 1607/Server 2016 (10.0.14393.8868), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313) (Microsoft MSRC). CISA mandated federal agencies apply patches by March 3, 2026 (CISA KEV). As interim mitigations, organizations should implement email filtering to block .lnk and suspicious HTML attachments, enforce user awareness training to avoid opening unsolicited files, and consider restricting execution of scripts and HTML files in email clients.

Community reactions

The vulnerability received significant attention from the security community as one of six actively exploited zero-days patched in Microsoft's February 2026 Patch Tuesday. Tenable's Satnam Narang highlighted it as a critical priority, and Akamai published a detailed exploit analysis blog post that was widely shared on Reddit's r/blueteamsec and r/SecOpsDaily communities (Tenable, Akamai Analysis). The subsequent attribution to APT28 in early March 2026 generated broad media coverage across The Hacker News, Security Affairs, SC World, and Forbes, with security researchers on social media emphasizing the geopolitical implications of Russian state-sponsored exploitation targeting NATO allies (The Hacker News APT28, Security Affairs). Trend Micro's subsequent PRISMEX campaign report further elevated community concern about the ongoing threat actor activity (Trend Micro).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management