Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513
Feb. 25, 2026, 11:56 a.m.
Description
This analysis examines CVE-2026-21513, a security bypass vulnerability in Microsoft's MSHTML framework, patched in February 2026. The flaw, actively exploited by Russian state-sponsored actor APT28, affects all Windows versions and has a CVSS score of 8.8. Using PatchDiff-AI, researchers identified the root cause in ieframe.dll's hyperlink navigation handling, allowing arbitrary file execution outside the browser's security context. The exploit involves a crafted Windows Shortcut file embedding HTML, communicating with APT28-linked infrastructure. It bypasses security measures like Mark of the Web and IE Enhanced Security Configuration through nested iframes and DOM manipulation, ultimately invoking ShellExecuteExW for out-of-sandbox execution.
Tags
Date
- Created: Feb. 25, 2026, 11:46 a.m.
- Published: Feb. 25, 2026, 11:46 a.m.
- Modified: Feb. 25, 2026, 11:56 a.m.
Indicators
- aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa
Attack Patterns
Additional Informations
- wellnesscaremed.com
- Russian Federation