Summary
Microsoft's MSHTML Framework contains a protection mechanism failure in hyperlink navigation handling. A malicious .LNK file or crafted HTML content can abuse nested iframe and DOM navigation to push attacker-controlled URLs into a shell-execution path, bypassing Mark of the Web and Internet Explorer Enhanced Security Configuration. The attack requires the victim to open the crafted file or content, and in-the-wild exploitation has been observed.
Why Planned Fix?
4/6Exploitation Details
Bypass browser security boundaries and execute attacker-controlled content outside the sandbox.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft Windows | Windows 10 1607, 1809, 21H2, 22H2; Windows 11 23H2, 24H2, 25H2; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2022 23H2, 2025 |
Desktop and server operating system that includes the legacy MSHTML/IEFRAME web-rendering engine used by Internet Explorer and embedded browser controls.
Affected ComponentHyperlink navigation handling in ieframe.dll/MSHTML, including embedded WebBrowser and HTML file navigation flows that can pass attacker-controlled URLs to ShellExecuteExW.
Hyperlink navigation handling in ieframe.dll/MSHTML, including embedded WebBrowser and HTML file navigation flows that can pass attacker-controlled URLs to ShellExecuteExW.
Not available
Apply the February 2026 Microsoft Windows security update for your affected release; the fix is delivered as the applicable KB cumulative update for each supported Windows and Windows Server build.
Apply the February 2026 Microsoft Windows security update for your affected release; the fix is delivered as the applicable KB cumulative update for each supported Windows and Windows Server build.
Not available
Probability of exploitation in the next 30 days
Worse than 96% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (23)
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
- •cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
- •cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:-:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:-:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | Security Update Guide - CVE-2026-21513 |
| akamai.com | Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513 |
| nvd.nist.gov | CVE-2026-21513 Detail |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| microsoft.com | February 2026 Security Update |
| www.tenable.com | CVE-2026-21513 |
| www.rapid7.com | Microsoft Windows: CVE-2026-21513: MSHTML Framework Security Feature Bypass Vulnerability |
| blog.qualys.com | Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review |
Priority History
Initial analysis