Microsoft issued an urgent fix for an actively exploited MSHTML (Trident) security feature bypass tracked as CVE-2026-21513 (CVSS 8.8), which allows attackers to circumvent Windows security prompts and protections without requiring elevated privileges. Reported exploitation relies on social engineering to get a user to open specially crafted content—such as malicious HTML or shortcut (.lnk) files—delivered via email attachments, links, or downloads; the weakness is described as a protection mechanism failure (CWE-693) in how Windows Shell and MSHTML handle embedded content and validation.
CISA added CVE-2026-21513 to the Known Exploited Vulnerabilities (KEV) catalog with required action to apply vendor mitigations/patches per Microsoft guidance and a remediation due date of 2026-03-03, reinforcing that exploitation is occurring and prioritization is warranted. Separate reporting also described other Microsoft zero-days patched in the same timeframe—Microsoft Word OLE mitigation bypass (CVE-2026-21514) and a Windows Desktop Window Manager (dwm.exe) privilege escalation (CVE-2026-21519)—but those are distinct vulnerabilities and not part of the MSHTML-specific KEV entry.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-21513 to its Known Exploited Vulnerabilities catalog, confirming federal agencies should prioritize remediation. The KEV entry set a remediation deadline of March 3, 2026 and directed organizations to apply Microsoft's mitigations.
On February 10, 2026, Microsoft shipped security updates addressing CVE-2026-21513 for supported Windows versions including Windows 10, Windows 11, and multiple Windows Server editions. The patch remediated the MSHTML/Windows Shell handling issue that could enable execution without proper security validation.
Microsoft identified CVE-2026-21513 in the MSHTML (Trident) framework as a security feature bypass vulnerability and stated it had been publicly disclosed and actively exploited in the wild before a fix was available. The flaw could let attackers bypass Windows execution prompts by luring users into opening crafted HTML or malicious shortcut files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourcewindowsforum.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.