MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update
ID: 57286a00-207c-5165-94b3-636918c5d48b
STIX ID: report--57286a00-207c-5165-94b3-636918c5d48b
Feed Name: GBHackers
Threat Score
**Executive Summary:** Microsoft disclosed and patched CVE-2026-21513, a high-severity MSHTML (ieframe.dll) security feature bypass actively exploited by APT28 via malicious .lnk files that embed hidden HTML payloads; the exploit enables sandbox escape and arbitrary code execution by forcing ShellExecuteExW calls and retrieves multistage malware from attacker infrastructure, prompting urgent patching and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
