Skip to content
Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability

Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability

First seen 12 Feb 2026, 21:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Microsoft has released a critical security patch for a zero-day vulnerability (CVE-2026-21513) in the MSHTML Framework, which was actively exploited before the fix was available. This vulnerability allows attackers to bypass Windows security features without elevated privileges, potentially affecting millions of systems. The flaw was added to the CISA KEV list on the same day it was published.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-10
CVE-2026-21513 published
2026-02-10
CVE-2026-21513 added to CISA KEV (active exploitation)
2026-02-11
Microsoft released security patch for CVE-2026-21513

More articles in this cluster (2)

Following this threat?

Track Microsoft and CVE-2026-21513 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed