CVE-2026-21513Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 64 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 153 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 203 mentions across 51 observed days

What's happening

  • Active exploitation reported across 153 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 76 signals
  • Technical details provided in 119 signals
  • General: 22 classified signals
  • Peaked 37d ago at 64 mentions (2026-03-02); latest day: 1
  • 203 total mentions across 51 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline203 mentions / 51d
016324864Mentions · 2026-02-10: 8Mentions · 2026-02-11: 14Mentions · 2026-02-12: 8Mentions · 2026-02-13: 3Mentions · 2026-02-14: 1Mentions · 2026-02-16: 2Mentions · 2026-02-17: 4Mentions · 2026-02-18: 2Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 4Mentions · 2026-02-25: 3Mentions · 2026-03-02: 64Mentions · 2026-03-03: 23Mentions · 2026-03-04: 5Mentions · 2026-03-05: 4Mentions · 2026-03-09: 2Mentions · 2026-03-10: 3Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-19: 1Mentions · 2026-03-26: 2Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-04-02: 3Mentions · 2026-04-05: 1Mentions · 2026-04-08: 9Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-13: 3Mentions · 2026-05-16: 1Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Mentions · 2026-05-30: 1Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-03-02: 3PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-03-02: 2Exploit Tool / Code · 2026-03-04: 1Exploit Tool / Code · 2026-04-08: 1Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-05-13: 1Active Exploitation · 2026-02-10: 2Active Exploitation · 2026-02-11: 10Active Exploitation · 2026-02-12: 4Active Exploitation · 2026-02-13: 2Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-16: 2Active Exploitation · 2026-02-17: 2Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-24: 3Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-02: 58Active Exploitation · 2026-03-03: 20Active Exploitation · 2026-03-04: 4Active Exploitation · 2026-03-05: 3Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 2Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 2Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-01: 2Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-08: 6Active Exploitation · 2026-04-09: 2Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-05-07: 2Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-13: 2Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-05-30: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-11: 7Patch / Workaround · 2026-02-12: 6Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-16: 2Patch / Workaround · 2026-02-17: 4Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-02: 27Patch / Workaround · 2026-03-03: 9Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-24: 1Technical Details · 2026-02-10: 7Technical Details · 2026-02-11: 9Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 2Technical Details · 2026-03-02: 46Technical Details · 2026-03-03: 13Technical Details · 2026-03-04: 5Technical Details · 2026-03-05: 3Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-13: 102-1002-1602-2303-0403-1203-2704-0104-1104-2905-2406-22
Signal classification6 categories
Active Exploitation
14169.5%
Patch
2512.3%
General
2210.8%
Disclosure
115.4%
PoC
31.5%
Exploit
10.5%
Referenced assets134 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-108
Active Exploitation2Disclosure2General2Patch2
2026-02-1114
Active Exploitation8Disclosure1General1Patch4
2026-02-128
Active Exploitation4General1Patch3
2026-02-133
Active Exploitation1Patch2
2026-02-141
Active Exploitation1
2026-02-162
Active Exploitation1Patch1
2026-02-174
Active Exploitation1Patch3
2026-02-182
Disclosure1Patch1
2026-02-191
Patch1
2026-02-201
Patch1
2026-02-231
Active Exploitation1
2026-02-244
Active Exploitation3General1
2026-02-253
Active Exploitation1General2
2026-03-0264
Active Exploitation56Disclosure1General4Patch3
2026-03-0323
Active Exploitation19Disclosure2General1Patch1
2026-03-045
Active Exploitation3Disclosure1Exploit1
2026-03-054
Active Exploitation3General1
2026-03-092
Active Exploitation1General1
2026-03-103
Active Exploitation1General1Patch1
2026-03-111
Patch1
2026-03-121
Active Exploitation1
2026-03-141
Active Exploitation1
2026-03-161
General1
2026-03-191
Active Exploitation1
2026-03-262
Active Exploitation1Disclosure1
2026-03-272
Active Exploitation2
2026-03-281
Active Exploitation1
2026-03-291
Active Exploitation1
2026-03-301
Active Exploitation1
2026-03-311
Active Exploitation1
2026-04-012
Active Exploitation2
2026-04-023
Active Exploitation1General2
2026-04-051
Active Exploitation1
2026-04-089
Active Exploitation6Disclosure1General1PoC1
2026-04-092
Active Exploitation2
2026-04-111
Active Exploitation1
2026-04-131
PoC1
2026-04-151
Active Exploitation1
2026-04-272
Active Exploitation1Disclosure1
2026-04-281
Active Exploitation1
2026-04-291
Active Exploitation1
2026-05-072
Active Exploitation2
2026-05-081
Active Exploitation1
2026-05-133
Active Exploitation2General1
2026-05-161
PoC1
2026-05-241
Patch1
2026-05-271
Active Exploitation1
2026-05-301
Active Exploitation1
2026-06-131
General1
2026-06-151
Active Exploitation1
2026-06-221
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 Microsoft fixed CVE-2026-21513 (CVSS 8.8) in February after confirming zero-day exploitation in MSHTML. A flaw in ieframe.dll let attackers bypass Mark-of-the-Web and IE ESC, enabling potential code execution. Akamai linked a malicious LNK sample to infrastructure associated with APT28. 🔗 Read → https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html

    Post summary

    Microsoft patched CVE‑2026‑21513 after confirming zero‑day exploitation in MSHTML, with a flaw in ieframe.dll that bypassed security features and allowed potential code execution; Akamai linked a malicious LNK sample to APT28 infrastructure.

    47312456223.8K
    1.1M followersView on X
  • blackorbird@blackorbird
    General

    #APT28 + CVE-2026-21513 (A security features bypass vulnerability within MSHTML framework.)= http://document.doc.LnK.download wellnesscaremed[.]com https://t.co/1HGSyuT4Sx

    Post summary

    The tweet references CVE-2026-21513, a security features bypass in MSHTML, but offers only a brief technical description without evidence of PoC, exploit, or patch.

    0260105476.4K
    40.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ APT28 is targeting Ukraine and allied supply chains using a confirmed zero-day (CVE-2026-21513) and PRISMEX malware. It also exploits CVE-2026-21509, with LNK delivery possibly chaining both flaws to enable theft and file-wiping. 🔗 Read here → https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html

    Post summary

    The post reports that APT28 is actively exploiting CVE-2026-21513 and CVE-2026-21509 against Ukraine, using PRISMEX malware delivered via LNK files to facilitate theft and file-wiping.

    14541011913.6K
    1.6M followersView on X
  • Akamai Security Intelligence Group@akamai_research
    Active Exploitation

    CVE-2026-21513 is already being exploited in the wild. Using PatchDiff-AI, we analyzed how a malicious .LNK can abuse MSHTML to bypass security boundaries and achieve code execution in activity linked to APT28. Full analysis: https://www.akamai.com/blog/security-research/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis?utm_source=twitter&utm_medium=social_corporate&utm_campaign=f-mc-62075

    Post summary

    CVE-2026-21513 is actively exploited in the wild via malicious .LNK files abusing MSHTML, with detailed analysis available but no patch or PoC disclosed.

    124070456.5K
    25.6K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    ⚠️ Active Zero-Day in MSHTML Lets Attackers Bypass Windows Security Prompts https://cybersecuritynews.com/mshtml-framework-0-day-vulnerability/ Microsoft has patched a critical zero-day (CVE-2026-21513) in the MSHTML (Trident) engine that was already being exploited in the wild. The flaw lets attackers bypass Windows security prompts with a single click, using malicious HTML or .lnk files delivered via email or links. CISA has added it to the KEV list. Patching should be a priority across Windows environments. #ZeroDay #WindowsSecurity #ThreatIntelligence

    Post summary

    CVE‑2026‑21513 is a zero‑day in the MSHTML engine that allows bypass of Windows security prompts and is being exploited in the wild; Microsoft has released a patch and CISA has added it to the KEV list, making immediate remediation essential.

    022160284.4K
    4.8K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html https://t.co/xFIHTOgJRd

    Post summary

    Just two URLs are provided with no substantive information about the CVE; therefore the content is general and offers no actionable details.

    27134294.2K
    120.5K followersView on X
  • Gen Threat Labs@GenThreatLabs
    General

    🎯 The #APT36 🇵🇰 cluster can't stop, won't stop. They just added #CVE-2026-21509 and #CVE-2026-21513 (borrowed from APT28) onto their delivery chain, pushing updated FIREPOWER via weaponized RTF and LNKs against 🇮🇳 targets. Separately, fresh SheetCreep + a shiny new CrystalShell-Slack variant co-dropped on a Kashmir target, because one implant is never enough. The vibeware factory is running three shifts: Crystal, .NET and PowerShell. Stay safe! IoCs 6df13b336f3daccc29a5f24bd5824f4ae9b4d7c45ee9c9adcd7a36679ee009c5 - CVE-2026-21509 558dd73f708d4ea7b33fec295ac201ee5c76ba293856d8835225538c11ff208e - CVE-2026-21513 9a93231038c7807c7c1376de1546cae94b6778106bb2ef115631da0991adbb91 - FIREPOWER 12335f9a1b7d3b84d2844b42f6f2ae03b70c2cc3d68e6c2dd468ee1ec6b2f3c1 - CrystalShell 3d74a0fb447590ba7c054e6e7c6d182d145651f588aa4de8bf0972461d9652f2 - SheetCreep

    Post summary

    The post reveals that APT36 has incorporated CVE‑2026‑21509 and CVE‑2026‑21513 into its delivery chain, sharing associated hashes but offering no technical details or exploitation evidence.

    19029183.3K
    4.7K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    It seems to me that Microsoft just issued additional 3 patches to address the weaknesses in the original Office CVE-2026-21509/zero-day exploit chain. Microsoft Word Security Feature Bypass Vulnerability (CVE-2026-21514) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 MSHTML Framework Security Feature Bypass Vulnerability (CVE-2026-21513) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513 Microsoft Office Security Feature Bypass Vulnerability (CVE-2026-21509) - the original one https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509

    Post summary

    Microsoft released three new patches to address the weaknesses in the original Office CVE-2026-21509 zero-day exploit chain, covering Word, Windows Shell, and MSHTML security feature bypass vulnerabilities.

    18033114.0K
    8.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 6 vulnerabilities to the KEV Catalog CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability: Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability: Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability: Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability: Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability: Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.

    Post summary

    CISA announced the addition of six Microsoft CVEs to the KEV catalog, providing concise technical details of each vulnerability without mentioning PoCs, exploits, or patches.

    09124104.8K
    164.8K followersView on X
  • Mr. Link@MrLinkEc
    Active Exploitation

    ¿Actualizaste ya tu Windows? Zero-Day Confirmado CVE-2026-21513 🚨 Se confirmó explotación activa de CVE-2026-21513, una vulnerabilidad en el motor MSHTML de Windows que permite eludir mecanismos de protección cuando el usuario abre un archivo HTML o un acceso directo (.LNK) malicioso. 🔎 ¿Qué ocurre técnicamente? El fallo (CWE 693 Protection Mechanism Failure) permite que contenido controlado por el atacante se procese sin aplicar correctamente controles de seguridad como validaciones de zona o advertencias. Con solo abrir el archivo (vector típico: phishing), el atacante puede ejecutar código en el contexto del usuario. 📊 Severidad: CVSS 8.8 (Alta) ⚠️ No requiere privilegios elevados 🎯 Impacto: Compromiso de confidencialidad, integridad y posible despliegue de malware 📌 Ya está siendo explotada en el mundo real 🛡️ ¿Qué hacer? ✔ Aplicar de inmediato los parches publicados por Microsoft en el Patch Tuesday de febrero 2026 ✔ Restringir apertura de .LNK y .HTML desde fuentes externas ✔ Monitorear procesos como mshta.exe e ieframe.dll ✔ Reforzar EDR y filtros antiphishing Si no has actualizado, tu dispositivo puede ser la puerta de entrada. Actualiza hoy!! #NoseDejenHackear 😎

    Post summary

    The post announces that CVE‑2026‑21513 is actively exploited in the wild, details its technical impact, and urges immediate patching and mitigation steps.

    11012372.6K
    55.8K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    ⚠️ APT28 Linked to MSHTML Zero-Day Exploited Before Patch https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html Microsoft patched CVE-2026-21513, a high-severity MSHTML flaw, in February, but signs point to zero-day exploitation beforehand. The bug allows attackers to bypass security features and potentially execute code via malicious HTML or LNK files. Artifacts uploaded in late January are tied to infrastructure linked to APT28, suggesting targeted use in real campaigns. The technique can bypass Window's MOTW protections, showing ongoing risks around file-based phishing and MSHTML abuse. #ZeroDay #APT28 #ThreatIntelligence

    Post summary

    APT28 is linked to real‑world exploitation of CVE‑2026‑21513 before Microsoft patched it, with evidence of malicious HTML/LNK files used in targeted campaigns.

    2602171.3K
    5.0K followersView on X
  • DigiByte Developers@DGBDevs
    Active Exploitation

    APT28 weaponized CVE-2026-21513 — MSHTML zero-day (CVSS 8.8) — exploited in the wild before Microsoft's Feb 2026 patch. Zero-days thrive in complex, closed-source frameworks. $DGB consensus: MIT-licensed C++, 12 years of public scrutiny. Attack surface matters.

    Post summary

    APT28 weaponized CVE-2026-21513 was actively exploited in the wild before Microsoft released a patch, underscoring the urgency of applying the February 2026 fix.

    040241991
    1.4K followersView on X
  • dmpdump@G60930953
    Active Exploitation

    Possible India-nexus #APT activity (#Sidewinder?) exploiting CVE‑2026‑21509 and CVE-2026-21513. @ElementalX2 https://t.co/YtlZc7ORhp

    Post summary

    The tweet indicates a possible APT activity targeting CVE-2026-21509 and CVE-2026-21513, but provides no supporting PoC, exploit code, or mitigation details.

    0511833.9K
    1.2K followersView on X
  • Szabolcs Schmidt@smica83
    PoC

    Related one seen from Spain @abuse_ch 'Briefing material for bilateral meeting of visiting Delegation.doc' CVE-2026-21509 exploit https://bazaar.abuse.ch/sample/507d40eb1542e9c2a763b765a540153cca93e9b86dbbf4004f28939290bb1135/ Next stage from the below #opendir 'R.LNk' CVE-2026-21513 exploit https://bazaar.abuse.ch/sample/7f9b6612138b7b47598669e6e57b417854d921b1557a4f28139cc948907cace8/ https://t.co/z9jCWP8V2n

    Post summary

    The tweet announces that exploit samples for CVE-2026-21509 and CVE-2026-21513 have been made available, providing practical PoC evidence but no further technical details, patch information, or evidence of active attacks.

    131834.0K
    3.7K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    ロシア系APT28が、Microsoft修正済みのゼロデイ脆弱性を悪用していた可能性が浮上した。MSHTMLの欠陥を突き、細工したLNK経由で保護機構を回避しコード実行に至る攻撃が確認された。 問題はCVE-2026-21513(CVSS 8.8)で、MSHTML Frameworkにおけるセキュリティ機能バイパスに起因する。Microsoftは2026年2月の月例更新で修正したが、実際の攻撃でゼロデイとして悪用されていたと認めている。Akamaiによれば、1月30日にVirusTotalへ投稿された不審な検体がAPT28関連インフラと結び付いていた。この欠陥はieframe.dllのハイパーリンク処理におけるURL検証不足が原因で、攻撃者制御の入力がShellExecuteExWを呼び出す経路に到達する。具体的にはHTMLを埋め込んだ細工済みLNKファイルを開かせ、ネストしたiframeなどで信頼境界を操作し、Mark-of-the-WebやIE ESCを回避する。これによりブラウザーのサンドボックス外で不正コード実行が可能となる。関連してCVE-2026-21509を悪用する攻撃も報告されている。 https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html

    Post summary

    APT28 is reported to have actively exploited CVE-2026-21513, a Microsoft MSHTML flaw patched in February 2026, with detailed technical information on the vulnerability and attack method.

    0401011.3K
    11.6K followersView on X
  • 📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中@MalwareBibleJP
    Active Exploitation

    MicrosoftのMSHTML Frameworkにゼロデイ脆弱性(CVE-2026-21513)が見つかり、パッチ提供前から実際の攻撃に悪用されていたことが確認されています。 細工されたHTMLファイルやショートカット(.lnk)ファイルをユーザーが開くと、本来表示されるはずのWindowsのセキュリティ警告がバイパスされ、ワンクリックで危険な処理が実行される仕組み。 攻撃に特権は不要で複雑性も低く、ユーザーの操作を起点としOSの保護機構を無効化する点で、フィッシングやマルウェア配布の成功率を構造的に引き上げる脆弱性といえます。 セキュリティ警告の表示そのものが回避される脆弱性ですので、怪しいファイルには注意するというユーザー側の判断に依存している環境ほど影響もありそうで、影響範囲もWindowsの全サポート対象バージョンに及ぶため、早期のパッチ適用など技術的対策の優先度を再確認すべき事案ですね。 【経緯のまとめ】 ・MSHTML Framework(別名Trident)は、Microsoftが提供するWindows標準のHTMLレンダリングエンジンであり、OS上の各種アプリケーションでWebコンテンツの表示に広く使われているコンポーネント。 ・CVE-2026-21513はセキュリティ機能バイパスの脆弱性で、CWE-693(Protection Mechanism Failure)に分類。CVSSスコアは8.8(攻撃元区分:ネットワーク、攻撃条件の複雑さ:低、必要な特権:なし、ユーザー関与:要)。 ・攻撃者は細工したHTMLファイルや悪意ある.lnkファイルを、メール添付・不正リンク・ダウンロード等で配布。ユーザーがこれらを開くと、Windows ShellとMSHTMLが埋め込みコンテンツを処理する過程でセキュリティ検証が正しく機能せず、実行確認のプロンプトが表示されないまま処理が進む。 ・Microsoftはパッチ提供前に本脆弱性が公開済みかつ実際に悪用されていたことを認めている。 ・2026年2月10日のPatch Tuesdayで修正パッチが公開。影響範囲はWindows 10、Windows 11、Windows Server 2012〜2025の全サポート対象バージョン。 ・米CISAは本脆弱性をKEVカタログに追加し、連邦政府機関に対して2026年3月3日までの修正適用を義務づけ。 ・悪用に成功した場合、不正なコード実行、ランサムウェア展開、認証情報の窃取、データ侵害、システムの完全な侵害に至る可能性。 https://cybersecuritynews.com/mshtml-framework-0-day-vulnerability/

    Post summary

    CVE-2026-21513 is a zero‑day MSHTML vulnerability that bypasses Windows security warnings and has been actively exploited before patching. Microsoft released a fix on 2026‑02‑10, and CISA has added the flaw to its KEV catalog, urging federal agencies to patch immediately.

    020112934
    4.9K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗙𝗲𝗯𝗿𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 February brings 𝟲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀, primarily focused on security feature bypass and privilege escalation. 𝗧𝗿𝗮𝗰𝗸𝗲𝗱 𝗖𝗩𝗘𝘀: 🔸 CVE-2026-21514 🔸 CVE-2026-21510 🔸 CVE-2026-21513 🔸 CVE-2026-21525 🔸 CVE-2026-21533 🔸 CVE-2026-21519 Multiple SYSTEM-level 𝗲𝗹𝗲𝘃𝗮𝘁𝗶𝗼𝗻-𝗼𝗳-𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 issues and 𝘂𝘀𝗲𝗿-𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝗼𝗻 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁 𝗮𝘁𝘁𝗮𝗰𝗸𝘀 are already being exploited in the wild — making endpoint patch prioritization critical. 𝗙𝘂𝗹𝗹 𝗯𝗿𝗲𝗮𝗸𝗱𝗼𝘄𝗻 and insights available in this month’s 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁: 🔗 https://horizon-secured.com/newsletter/ #HorizonAlert #Cybersecurity #PatchTuesday #ZeroDay

    Post summary

    Six CVEs (2026‑21514, 21510, 21513, 21525, 21533, 21519) are actively exploited for privilege escalation, underscoring the urgency of endpoint patching.

    020931.1K
    2.2K followersView on X
  • 阿绎 AYi@AYi_AInotes
    Active Exploitation

    Theo 这张清单刷屏了,近期的安全事件如下: CopyFail(Linux 系统被破解) CopyFail 2/Dirty Frag(Linux 内核脏碎片漏洞) Next.js 框架出现 13 个安全警告 MacOS 26.5 系统修复了 70 多个通用漏洞披露(CVE)漏洞 iOS 26.5 系统修复了约 50 个通用漏洞披露(CVE)漏洞 YellowKey(Windows Bitlocker 全盘加密被破解) GreenPlasma(Windows 权限提升漏洞) CVE-2026-21510 和 CVE-2026-21513 被证实由俄罗斯用于 Windows 远程代码执行漏洞攻击 CVE-2026-32202 被单独证实由俄罗斯用于获取敏感文档 Mini-Shai Hulud(超过 300 个 JS 和 Python 软件包因 GitHub Action 缓存投毒而被入侵) 谷歌证实,他们发现了利用人工智能对某个未知的 “开源、基于 Web 的系统管理工具” 进行零日漏洞攻击的情况 Canvas(大多数学校使用的流行学习管理系统)被完全破解 PAN-OS( Palo Alto Networks 公司的操作系统)因严重等级为 9.3 的 CVE-2026-0300 漏洞被破解 我连着看了三天相关报告,越看越觉得这不是个危言耸听的恐怖故事, 更像是软件工程进入后AI安全时代的入学通知。 最关键的信号藏在 CopyFail 里: 一个 732 字节的 Python 脚本, 确定性拿下 2017 年后几乎所有 Linux 发行版的 root。 这玩意竟然是 AI 辅助发现的。 Google 也在同一周确认,AI 驱动的零日已经在野利用了, 俄罗斯 APT 直接武器化两个 Windows CVE, Mini-Shai Hulud 一次劫持 300+ 个 JS/Python 包。 以前一个漏洞躺三年才被人发现, 现在 AI 扫描+AI 利用,未知→已知→武器化几乎同步发生。 更狠的是供应链, Mini-Shai Hulud 告诉所有人一件事: 你信任的 CI/CD 才是最大的后门。 你以为用官方 GitHub Action 就安全, 其实是把 OIDC token 的钥匙拱手送给攻击者。 Perry Metzger 说过一句我反复琢磨的话: bug 的总量是有限的,AI 正在快速耗尽低挂果实。 也就是说,以前安全是"被动 patch", 现在开始转向"AI 实时免疫"。 未来不再是人盯人,会变成 AI 盯 AI。 所以 Theo 问 Are you scared yet, 我的答案是不怕,但必须立刻行动。 第一步不是全站 patch,是把供应链审计提到 P0, GH Actions 全审一遍,禁用 pull_request_target, 强制 SLSA Level 3,启用 SBOM。 那些把"安全作为第一原则"写进 DNA 的团队, 接下来 3-5 年会活得最舒服, 其他人要交的学费,可能比想象中贵得多~

    Post summary

    The post reports that several CVEs—including high‑severity Windows and Linux flaws—are actively exploited, aided by AI‑generated tools, and notes patches for some affected systems.

    700331.1K
    44.0K followersView on X
  • MalwareHunterTeam@malwrhunterteam
    General

    Related "Agenda.doc" was seen from Pakistan and tagged as CVE-2026-21509. Related "Q.LnK" tagged as CVE-2026-21513. 🤷‍♂️ https://t.co/tqUZExYWmU

    Post summary

    The tweet simply notes that files named "Agenda.doc" and "Q.LnK" were seen in Pakistan, tagged with CVE-2026-21509 and CVE-2026-21513, without providing any technical, exploit, or patch-related information.

    230423.5K
    254.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/10追加) 🛡️No.1509 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、悪意のあるリンクやショートカットファイルを介して、リモートよりWindows SmartScreen および Windows Shell のセキュリティプロンプトをバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 🛡️No.1510 CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability ============= CVSSスコア: 8.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、細工されたHTMLファイルやショートかっとファイルを介して、リモートから、セキュリティ機能をバイパスされる恐れがあります。 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 🛡️No.1511 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:セキュリティ決定の信頼できない入力への依存 (CWE-807/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、Officeファイルを介してローカル上でSYSTEM権限を取得される恐れがります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 🛡️No.1512 CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:型の取り違え (CWE-843/ Microsoft Corporation) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 🛡️No.1513 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability ============= CVSSスコア: 6.2 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 種別:NULL ポインタデリファレンス (CWE-476 / Microsoft Corporation) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上でDoSを発生させられる恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 🛡️No.1514 CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability ============= CVSSスコア: 7.8 (Base) / Microsoft Corporation CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:不適切な権限管理 (CWE-269 / Microsoft Corporation) 深刻度:深刻🔥 ---------------------- 悪用時影響: 認証済みの攻撃者により、ローカル上でSYSTEM権限を取得される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed that six Microsoft CVEs are actively exploited and added them to its KEV catalog, providing Microsoft advisory links and vulnerability details, but no PoC, exploit code, or patch information is disclosed.

    000834.7K
    42.5K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016--x64
OSmicrosoftwindows_server_2019--x64
OSmicrosoftwindows_server_2022--x64
OSmicrosoftwindows_server_2022_23h2--x64
OSmicrosoftwindows_server_2025--x64

Explore more