Russia-linked APT28 exploited MSHTML zero-day CVE-2026-21513 before patch
ID: 15f16159-6119-583d-b04d-9f662b042eac
STIX ID: report--15f16159-6119-583d-b04d-9f662b042eac
Feed Name: Security Affairs
Akamai and Microsoft reported that Russia-linked APT28 exploited a high-severity MSHTML zero-day (CVE-2026-21513, CVSS 8.8) before Microsoft’s February 2026 patch. The attackers used specially crafted Windows Shortcut (.lnk) files embedding HTML to downgrade security context, bypass Mark of the Web and IE ESC, and invoke ShellExecuteExW to execute code outside the browser sandbox; an exploit sample was uploaded to VirusTotal and tied to infrastructure (including wellnesscaremed.com) attributed to APT28. Microsoft patched the flaw by tightening hyperlink protocol validation to prevent dangerous links from reaching ShellExecuteExW.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
