Cybersecuritynews
Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability
First seen 12 Feb 2026, 21:16 UTC
•
•70% similarity
•48.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Microsoft has released a critical security patch for a zero-day vulnerability (CVE-2026-21513) in the MSHTML Framework, which was actively exploited before the fix was available. This vulnerability allows attackers to bypass Windows security features without elevated privileges, potentially affecting millions of systems. The flaw was added to the CISA KEV list on the same day it was published.
ThreatCluster AI
Timeline
2026-02-10
CVE-2026-21513 published
2026-02-10
CVE-2026-21513 added to CISA KEV (active exploitation)
2026-02-11
Microsoft released security patch for CVE-2026-21513