Related Threat Clusters
-
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
APT28 has actively exploited a zero-day vulnerability in MSHTML affecting all Windows versions, which has a CVSS score of 8.8. The vulnerability allows for security bypass and poses significant risks to users. A patch…
4 articles · Updated March 2, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Vulnerability in Notepad's Markdown Feature Allows Remote Code Execution
Researchers have discovered a vulnerability in Notepad's newly added Markdown support that can be exploited for remote code execution (RCE). This flaw, tracked as CVE-2026-20841 with a severity score of 8.8, was…
73 articles · Updated February 11, 2026 -
Microsoft Issues Urgent Patch for MSHTML Framework Zero-Day Vulnerability
Microsoft has released a critical security patch for a zero-day vulnerability (CVE-2026-21513) in the MSHTML Framework, which was actively exploited before the fix was available. This vulnerability allows attackers to…
2 articles · Updated February 11, 2026 -
Microsoft Addresses Six Actively Exploited Zero-Day Vulnerabilities
On February 10, 2026, Microsoft released a security update addressing 59 vulnerabilities, including six zero-day flaws that were actively exploited prior to the patch. The vulnerabilities affect various Microsoft…
70 articles · Updated February 10, 2026 -
Microsoft Addresses CVE-2026-21513 Zero-Day Exploit in February
Microsoft has resolved CVE-2026-21513, a vulnerability with a CVSS score of 8.8, after confirming its exploitation in the wild. The flaw, located in the MSHTML component and specifically in ieframe.dll, allowed…
2 articles · Updated March 2, 2026
Recent Intelligence Reports
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update — Cybersecuritynews · March 2, 2026
- Microsoft fixed CVE-2026-21513 (CVSS 8.8) in February after confirming zero — Facebook · March 2, 2026
- Microsoft issues urgent patches for actively exploited Windows, Office zero — Storyboard18 · February 12, 2026
- MSHTML Framework Zero-Day Opens Door to Network — Gbhackers · February 11, 2026
- February 2026 Patch Tuesday: Critical Microsoft CVEs & Fixes — Absolute · February 10, 2026