logo

Russia-linked APT28 exploited MSHTML zero-day CVE-2026-21513 before patch

ID: 15f16159-6119-583d-b04d-9f662b042eac

STIX ID: report--15f16159-6119-583d-b04d-9f662b042eac

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Akamai and Microsoft reported that Russia-linked APT28 exploited a high-severity MSHTML zero-day (CVE-2026-21513, CVSS 8.8) before Microsoft’s February 2026 patch. The attackers used specially crafted Windows Shortcut (.lnk) files embedding HTML to downgrade security context, bypass Mark of the Web and IE ESC, and invoke ShellExecuteExW to execute code outside the browser sandbox; an exploit sample was uploaded to VirusTotal and tied to infrastructure (including wellnesscaremed.com) attributed to APT28. Microsoft patched the flaw by tightening hyperlink protocol validation to prevent dangerous links from reaching ShellExecuteExW.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.