Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513

Feb. 25, 2026, 11:56 a.m.

Description

This analysis examines CVE-2026-21513, a security bypass vulnerability in Microsoft's MSHTML framework, patched in February 2026. The flaw, actively exploited by Russian state-sponsored actor APT28, affects all Windows versions and has a CVSS score of 8.8. Using PatchDiff-AI, researchers identified the root cause in ieframe.dll's hyperlink navigation handling, allowing arbitrary file execution outside the browser's security context. The exploit involves a crafted Windows Shortcut file embedding HTML, communicating with APT28-linked infrastructure. It bypasses security measures like Mark of the Web and IE Enhanced Security Configuration through nested iframes and DOM manipulation, ultimately invoking ShellExecuteExW for out-of-sandbox execution.

Date

  • Created: Feb. 25, 2026, 11:46 a.m.
  • Published: Feb. 25, 2026, 11:46 a.m.
  • Modified: Feb. 25, 2026, 11:56 a.m.

Indicators

  • aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa

Attack Patterns

Additional Informations

  • wellnesscaremed.com
  • Russian Federation

Linked vulnerabilities