logo

MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update

ID: a0e6a99b-44ec-5053-9367-2f05cf92e197

STIX ID: report--a0e6a99b-44ec-5053-9367-2f05cf92e197

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

**MSHTML Framework 0-day (CVE-2026-21513)**: Akamai researchers found that APT28 actively exploited a high-severity MSHTML vulnerability in ieframe.dll to bypass browser security (MotW/IE ESC) and execute arbitrary files via crafted .lnk files and nested iframes; Microsoft released a February 2026 Patch Tuesday fix and Akamai published related IOCs and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.