MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update
ID: a0e6a99b-44ec-5053-9367-2f05cf92e197
STIX ID: report--a0e6a99b-44ec-5053-9367-2f05cf92e197
Feed Name: cybersecurityNews.com
Threat Score
**MSHTML Framework 0-day (CVE-2026-21513)**: Akamai researchers found that APT28 actively exploited a high-severity MSHTML vulnerability in ieframe.dll to bypass browser security (MotW/IE ESC) and execute arbitrary files via crafted .lnk files and nested iframes; Microsoft released a February 2026 Patch Tuesday fix and Akamai published related IOCs and analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
