CVE-2026-21513CISA KEV
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
- Product
- Windows
- Added to KEV
- 10 Feb 2026
- Federal remediation due
- 3 Mar 2026
- Known ransomware use
- Not reported