logo

MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update

ID: 57286a00-207c-5165-94b3-636918c5d48b

STIX ID: report--57286a00-207c-5165-94b3-636918c5d48b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** Microsoft disclosed and patched CVE-2026-21513, a high-severity MSHTML (ieframe.dll) security feature bypass actively exploited by APT28 via malicious .lnk files that embed hidden HTML payloads; the exploit enables sandbox escape and arbitrary code execution by forcing ShellExecuteExW calls and retrieves multistage malware from attacker infrastructure, prompting urgent patching and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.