logo

MSHTML Framework 0-Day Vulnerability Let Attackers Security Feature over Network

ID: 2eb97af0-fb8e-579c-8a03-37cce5fab6aa

STIX ID: report--2eb97af0-fb8e-579c-8a03-37cce5fab6aa

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft released an urgent patch for CVE-2026-21513, a critical MSHTML (Trident) zero-day actively exploited to bypass Windows security prompts via crafted HTML and .lnk files; CVSS 8.8. The flaw affects supported Windows 10/11 and Server editions, is network-deliverable via social engineering, and has been added to CISA's Known Exploited Vulnerabilities list — organizations are advised to prioritize immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.