logo

APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday

ID: 7829b235-2247-551c-80f8-fa41520ee16e

STIX ID: report--7829b235-2247-551c-80f8-fa41520ee16e

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Akamai and Microsoft disclosed that CVE-2026-21513 (MSHTML security feature bypass, CVSS 8.8) was exploited as a zero-day in the wild; attackers (linked to APT28) used malicious LNK files embedding HTML to bypass Mark-of-the-Web and IE Enhanced Security Configuration, invoking ShellExecuteExW to execute local/remote resources outside the browser sandbox. Akamai identified a VirusTotal sample and infrastructure (wellnesscaremed.com) tied to the campaign, and Microsoft issued a patch in February 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.