LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21513 to its Known Exploited Vulnerabilities catalog on Feb 10, 2026, with a federal patch deadline of Mar 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

A protection mechanism failure in the Microsoft MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. The issue affects Microsoft Windows systems that rely on this framework for rendering or processing content. Organizations should treat the vulnerability as a potential route for attackers to circumvent intended controls until the flaw is addressed.

How it works

The weakness is categorized as CWE-693, a protection mechanism failure. In this class of issue, a control intended to restrict or validate actions does not operate as designed. An attacker can send specially formed network traffic that causes the MSHTML Framework to skip or ignore the protection, resulting in the bypass. No further mechanics are provided in the available summary; confirm the precise trigger conditions against the vendor advisory.

Am I affected? How to find it in your systems

MSHTML is a core component of Microsoft Windows used by multiple applications for HTML rendering and related tasks. Inventory all Windows endpoints and servers, paying particular attention to systems that process untrusted content through legacy or embedded browser engines. Check installed Windows updates and application versions against the vendor advisory to determine exposure. Because the flaw is reachable over the network, review firewall logs, web proxy records, and endpoint telemetry for unexpected inbound connections targeting MSHTML-related processes or ports. Specific indicators of exploitation are not listed in the summary; consult the advisory for any additional detection guidance.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review configurations that rely on MSHTML to ensure the restored protection mechanism is active. For the broader class of protection mechanism failures, organizations commonly reduce attack surface by disabling unnecessary legacy components, enforcing strict input validation at network boundaries, and limiting the use of features that process external content. Confirm the exact patch and configuration steps in the vendor advisory before deployment.

If you can't patch immediately

Follow the mitigations documented by the vendor. Where cloud services are involved, apply the controls required under CISA BOD 22-01. If mitigations cannot be implemented, discontinue use of the affected product or component until an update can be applied. Network segmentation that restricts traffic to MSHTML-dependent services can limit exposure while patches are prepared. Monitor for anomalous behavior that could indicate attempted bypasses.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and subsequent data exposure. Run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-693
Added to CISA KEVFeb 10, 2026
Federal patch deadlineMar 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities