CVE-2026-21513

high

Description

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

From the Tenable Blog

February 2026 Microsoft Patch Tuesday | Tenable®
February 2026 Microsoft Patch Tuesday | Tenable®

Published: 2026-02-10

Microsoft patched six zero-day vulnerabilities that were exploited in the wild including CVE-2026-21510 and CVE-2026-21513.

References

https://www.theregister.com/2026/04/29/microsoft_zero_click_exploit/

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-flaw-exploited-in-zero-day-attacks/

https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html

https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html

https://www.securityweek.com/incomplete-windows-patch-opens-door-to-zero-click-attacks/

https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html

https://securityaffairs.com/190510/apt/russia-linked-apt28-uses-prismex-to-infiltrate-ukraine-and-allied-infrastructure-with-advanced-tactics.html

https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html

https://securityaffairs.com/188782/security/russia-linked-apt28-exploited-mshtml-zero-day-cve-2026-21513-before-patch.html

https://www.malwarebytes.com/blog/news/2026/02/february-2026-patch-tuesday-includes-six-actively-exploited-zero-days

https://www.infosecurity-magazine.com/news/microsoft-six-zero-day-feb-2026/

https://www.helpnetsecurity.com/2026/02/11/february-2026-patch-tuesday/

https://thehackernews.com/2026/02/microsoft-patches-59-vulnerabilities.html

https://securityaffairs.com/187855/security/u-s-cisa-adds-microsoft-office-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://www.theregister.com/2026/02/10/microsofts_valentines_gift_to_admins/

https://www.securityweek.com/6-actively-exploited-zero-days-patched-by-microsoft-with-february-2026-updates/

https://www.cisa.gov/news-events/alerts/2026/02/10/cisa-adds-six-known-exploited-vulnerabilities-catalog

https://securityaffairs.com/187848/uncategorized/microsoft-patch-tuesday-security-updates-for-february-2026-fix-six-actively-exploited-zero-days.html

https://krebsonsecurity.com/2026/02/patch-tuesday-february-2026-edition/

https://cyberscoop.com/microsoft-patch-tuesday-february-2026/

Details

Source: Mitre, NVD

Published: 2026-02-10

Updated: 2026-03-30

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.27795