Microsoft has released an urgent security patch for a critical zero-day vulnerability (CVE-2026-21513) affecting the MSHTML Framework, which was actively exploited in the wild before a fix became available. The flaw allows attackers to bypass Windows security features without requiring elevated privileges, putting millions of systems at risk. CVE-2026-21513 is a security feature bypass vulnerability […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
