Skip to content

CVE-2026-21513

CVE

Threat entity extracted from intelligence sources

Frequency
18
occurrences
First Seen
February 10, 2026
Last Seen
April 29, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

APT28 has actively exploited a zero-day vulnerability in MSHTML affecting all Windows versions, which has a CVSS score of 8.8. The vulnerability allows for security bypass and poses significant risks to users. A patch was released in February 2026 to address this issue.

Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000 devices across 120 countries, allows attackers to intercept internet traffic and ste...

A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator privileges. The exploit targets a flaw in the Windows Defender update mechanism and...

Researchers have discovered a vulnerability in Notepad's newly added Markdown support that can be exploited for remote code execution (RCE). This flaw, tracked as CVE-2026-20841 with a severity score of 8.8, was addressed in Microsoft's latest Patch Tuesday updates. The exploitation requires social...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Clusters (10)

1 / 2

Related Articles (18)

1 / 4