Skip to main content

CVE-2026-21513

8.8
HIGHCVSS v3.1 Base Score
24.96%
LOW RiskEPSS (96th percentile)
KEV

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Published: 2/10/2026
Modified: 3/30/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Vendor / Product:

Microsoft Windows

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due Date: 3/3/2026(OVERDUE)
Added to KEV:

2/10/2026

Notes:

https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21513

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

24.96%LOW Exploitation Risk
96th percentile

This vulnerability has a 24.96% probability of being exploited in the next 30 days, ranking higher than 96% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-693)

CVE-2026-32202MEDIUM 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

4/14/2026
CVE-2026-21510HIGH 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

2/10/2026
CVE-2025-40536HIGH 8.1

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

1/28/2026
CVE-2025-69264HIGH 8.8

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism, git dependencies can still execute prepare, prepublish, and prepack scripts during the fetch phase, enabling remote code execution without user consent or approval. This issue is fixed in version 10.26.0.

1/7/2026
CVE-2025-68668CRITICAL 9.9

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n, using the same privileges as the n8n process. This issue has been patched in version 2.0.0. Workarounds for this issue involve disabling the Code Node by setting the environment variable NODES_EXCLUDE: "[\"n8n-nodes-base.code\"]", disabling Python support in the Code node by setting the environment variable N8N_PYTHON_ENABLED=false, which was introduced in n8n version 1.104.0, and configuring n8n to use the task runner based Python sandbox via the N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables.

12/26/2025

Similar SeverityHIGH