Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability

Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability

First seen 12 Feb 2026, 21:16 UTC GbhackersCybersecuritynews 70% similarity 48.6

Article Content

Browse articles
ThreatCluster

Microsoft has released a critical security patch for a zero-day vulnerability (CVE-2026-21513) in the MSHTML Framework, which was actively exploited before the fix was available. This vulnerability allows attackers to bypass Windows security features without elevated privileges, potentially affecting millions of systems. The flaw was added to the CISA KEV list on the same day it was published.

ThreatCluster AI

Timeline

2026-02-10
CVE-2026-21513 published
2026-02-10
CVE-2026-21513 added to CISA KEV (active exploitation)
2026-02-11
Microsoft released security patch for CVE-2026-21513

Community

Browse all →