s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-21513

📛 CVE Title

MSHTML Framework Security Feature Bypass Vulnerability

Description

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Overview

State
PUBLISHED
Assigner (CNA)
microsoft
CVSS severity
HIGH
CVSS score
CVSS 8.8 / 10 8.8 8.8 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Effective score
8.8 / 10 HIGH source: CNA overview
MSRC score
8.8 / 10 HIGH MS rating: Important · Security Feature Bypass
CWE(s)
CWE-693
Reserved
2025-12-30
Published
2026-02-10 08:00 UTC
Last updated
2026-02-10 08:00 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21513.json
Linked Threat
CVE-2026-21513 — Microsoft Windows: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Vendor / project
Microsoft
Product
Windows
Date added to KEV
2026-02-10
Remediation due
2026-03-03
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21513
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-02-10 18:16:33 UTC
NVD last modified
2026-03-30 13:28:07 UTC
NVD CVSS v3.1
CVSS 8.8 / 10 8.8 8.8 / 10 HIGH source: secure@microsoft.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability subscore
2.8 / 10
Impact subscore
5.9 / 10
EPSS score
0.2467 (probability of exploitation in next 30 days)
EPSS percentile
96.21% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD / KEV / EPSS data refreshed 2026-05-25 04:04 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-7342
Assigner
microsoft
Published
Feb 10, 2026, 5:51:26 PM
Updated
May 11, 2026, 9:25:25 PM
EUVD base score (CVSS 3.1)
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EUVD-reported EPSS
24.9600
Vendors
Microsoft
Products
Windows Server 2012 (Server Core installation) (6.2.9200.0 <6.2.9200.25923)
Windows 10 Version 21H2 (10.0.19044.0 <10.0.19044.6937)
Windows 10 Version 1607 (10.0.14393.0 <10.0.14393.8868)
Windows Server 2019 (Server Core installation) (10.0.17763.0 <10.0.17763.8389)
Windows Server 2016 (10.0.14393.0 <10.0.14393.8868)
Windows 11 version 26H1 (10.0.28000.0 <10.0.28000.1575)
Windows Server 2012 (6.2.9200.0 <6.2.9200.25923)
Windows Server 2012 R2 (6.3.9600.0 <6.3.9600.23022)
Windows 11 Version 23H2 (10.0.22631.0 <10.0.22631.6649)
Windows 10 Version 21H2 (10.0.19044.0 <10.0.19044.6937)
Windows 10 Version 22H2 (10.0.19045.0 <10.0.19045.6937)
Windows Server 2019 (10.0.17763.0 <10.0.17763.8389)
Windows Server 2022, 23H2 Edition (Server Core installation) (10.0.25398.0 <10.0.25398.2149)
Windows Server 2022 (10.0.20348.0 <10.0.20348.4773)
Windows 11 version 22H3 (10.0.22631.0 <10.0.22631.6649)
Windows Server 2012 (6.2.9200.0 <6.2.9200.25923)
Windows Server 2022, 23H2 Edition (Server Core installation) (10.0.25398.0 <10.0.25398.2149)
Windows Server 2025 (10.0.26100.0 <10.0.26100.32370)
Windows Server 2022 (10.0.20348.0 <10.0.20348.4773)
Windows Server 2016 (Server Core installation) (10.0.14393.0 <10.0.14393.8868)
Windows 11 Version 24H2 (10.0.26100.0 <10.0.26100.7840)
Windows Server 2019 (Server Core installation) (10.0.17763.0 <10.0.17763.8389)
Windows Server 2019 (10.0.17763.0 <10.0.17763.8389)
Windows 11 version 26H1 (10.0.28000.0 <10.0.28000.1575)
Windows Server 2025 (Server Core installation) (10.0.26100.0 <10.0.26100.32370)
Windows Server 2012 (Server Core installation) (6.2.9200.0 <6.2.9200.25923)
Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7840)
Windows 11 Version 23H2 (10.0.22631.0 <10.0.22631.6649)
Windows Server 2012 R2 (Server Core installation) (6.3.9600.0 <6.3.9600.23022)
Windows Server 2012 R2 (6.3.9600.0 <6.3.9600.23022)
Windows Server 2016 (Server Core installation) (10.0.14393.0 <10.0.14393.8868)
Windows 10 Version 1607 (10.0.14393.0 <10.0.14393.8868)
Windows 10 Version 1809 (10.0.17763.0 <10.0.17763.8389)
Windows 10 Version 22H2 (10.0.19045.0 <10.0.19045.6937)
Windows Server 2016 (10.0.14393.0 <10.0.14393.8868)
Windows 10 Version 1809 (10.0.17763.0 <10.0.17763.8389)
Windows Server 2012 R2 (Server Core installation) (6.3.9600.0 <6.3.9600.23022)
Windows 11 version 22H3 (10.0.22631.0 <10.0.22631.6649)
Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7840)
Windows Server 2025 (10.0.26100.0 <10.0.26100.32370)
Windows 11 Version 24H2 (10.0.26100.0 <10.0.26100.7840)
Windows 11 version 26H1 (10.0.28000.0 <10.0.28000.1575)
Windows Server 2025 (Server Core installation) (10.0.26100.0 <10.0.26100.32370)
Aliases
GHSA-rqf6-jf48-p6rm

ENISA description: Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-15 03:05 UTC (source: CVRF).

MS severity
Important
Impact
Security Feature Bypass
MS CVSS base score
8.8 / 10 (temporal 7.7)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploit assessment
Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected
Release
2026-Feb
Microsoft remediations / KB articles (28)
Microsoft FAQ (2)

According to the CVSS metric, the attack vector is user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability?

An attacker could exploit this vulnerability by convincing a user to open a malicious HTML file or shortcut (.lnk) file delivered through a link, email attachment, or download. The specially crafted file manipulates browser and Windows Shell handling, causing the content to be executed by the operating system. This allows the attacker to bypass security features and potentially achieve code execution.

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

This update address a vulnerability that bypasses prompts when executing a file.

Affected products (22)

VendorProductVersionsPlatforms
Microsoft Windows 10 Version 1607 10.0.14393.0 (affected) 32-bit Systems, x64-based Systems
Microsoft Windows 10 Version 1809 10.0.17763.0 (affected) 32-bit Systems, x64-based Systems
Microsoft Windows 10 Version 21H2 10.0.19044.0 (affected) 32-bit Systems, ARM64-based Systems, x64-based Systems
Microsoft Windows 10 Version 22H2 10.0.19045.0 (affected) 32-bit Systems, ARM64-based Systems, x64-based Systems
Microsoft Windows 11 version 22H3 10.0.22631.0 (affected) ARM64-based Systems
Microsoft Windows 11 Version 23H2 10.0.22631.0 (affected) x64-based Systems
Microsoft Windows 11 Version 24H2 10.0.26100.0 (affected) ARM64-based Systems, x64-based Systems
Microsoft Windows 11 Version 25H2 10.0.26200.0 (affected)
Microsoft Windows 11 version 26H1 10.0.28000.0 (affected) ARM64-based Systems
Microsoft Windows 11 Version 26H1 10.0.28000.0 (affected)
Microsoft Windows Server 2012 6.2.9200.0 (affected) x64-based Systems
Microsoft Windows Server 2012 (Server Core installation) 6.2.9200.0 (affected) x64-based Systems
Microsoft Windows Server 2012 R2 6.3.9600.0 (affected) x64-based Systems
Microsoft Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 (affected) x64-based Systems
Microsoft Windows Server 2016 10.0.14393.0 (affected) x64-based Systems
Microsoft Windows Server 2016 (Server Core installation) 10.0.14393.0 (affected) x64-based Systems
Microsoft Windows Server 2019 10.0.17763.0 (affected) x64-based Systems
Microsoft Windows Server 2019 (Server Core installation) 10.0.17763.0 (affected) x64-based Systems
Microsoft Windows Server 2022 10.0.20348.0 (affected) x64-based Systems
Microsoft Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 (affected) x64-based Systems
Microsoft Windows Server 2025 10.0.26100.0 (affected) x64-based Systems
Microsoft Windows Server 2025 (Server Core installation) 10.0.26100.0 (affected) x64-based Systems

Affected products — CPE 2.3 (23) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
  • cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
  • cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
  • cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
  • cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
  • cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*
  • cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*
  • cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:-:*:x64:*
  • cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:-:*:x64:*
  • cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (29)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (4)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cwe CWE-693 no local data 2026-05-14 02:58 UTC
cve CVE-2026-21513 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.tenable.com

      Microsoft patched six zero-day vulnerabilities that were exploited in the wild including CVE - 2026 -21510 and CVE-2026-21513 .

      2026-05-14 16:50 UTC
    • web:cybersecuritynews.com

      Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

      2026-05-14 16:50 UTC
    • web:msrc.microsoft.com

      Security Update Guide - Microsoft Security Response Center

      2026-05-14 16:50 UTC
    • web:nvd.nist.gov

      Official websites use .gov A .gov website belongs to an official government organization in the United States.

      2026-05-14 16:50 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-14 16:50 UTC
    • web:app.opencve.io

      Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the Microsoft update that fixes CVE‑2026‑21513 via Windows Update or the Microsoft Update Catalog.

      2026-05-14 16:50 UTC
    • web:www.cve.org

      Description Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

      2026-05-14 16:50 UTC
    • web:www.sentinelone.com

      CVE-2026-21513 is an authentication bypass vulnerability in Microsoft Windows 10 1607. Learn about its impact, affected versions, and mitigation methods.

      2026-05-14 16:50 UTC
    • CISA KEV

      Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-03 Known ransomware campaign use: Unknown

      2026-05-14 01:13 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2026-21513.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21513",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-11T04:55:53.740962Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-02-10",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21513"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T14:44:46.806Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21513"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-02-10T00:00:00.000Z",
                "value": "CVE-2026-21513 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-03-27T21:04:53.710Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21513-detection-script-security-feature-bypass-vulnerability-in-mshtml-framework"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21513-mitigation-script-security-feature-bypass-vulnerability-in-mshtml-framework"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Windows 10 Version 1607",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.14393.8868",
                  "status": "affected",
                  "version": "10.0.14393.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Windows 10 Version 1809",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.17763.8389",
                  "status": "affected",
                  "version": "10.0.17763.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "ARM64-based Systems",
                "x64-based Systems"
              ],
              "product": "Windows 10 Version 21H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.19044.6937",
                  "status": "affected",
                  "version": "10.0.19044.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "ARM64-based Systems",
                "x64-based Systems"
              ],
              "product": "Windows 10 Version 22H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.19045.6937",
                  "status": "affected",
                  "version": "10.0.19045.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "ARM64-based Systems"
              ],
              "product": "Windows 11 version 22H3",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.22631.6649",
                  "status": "affected",
                  "version": "10.0.22631.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows 11 Version 23H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.22631.6649",
                  "status": "affected",
                  "version": "10.0.22631.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "ARM64-based Systems",
                "x64-based Systems"
              ],
              "product": "Windows 11 Version 24H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.7840",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Windows 11 Version 25H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26200.7840",
                  "status": "affected",
                  "version": "10.0.26200.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "ARM64-based Systems"
              ],
              "product": "Windows 11 version 26H1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.28000.1575",
                  "status": "affected",
                  "version": "10.0.28000.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Windows 11 Version 26H1",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.28000.1575",
                  "status": "affected",
                  "version": "10.0.28000.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2012",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "6.2.9200.25923",
                  "status": "affected",
                  "version": "6.2.9200.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2012 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "6.2.9200.25923",
                  "status": "affected",
                  "version": "6.2.9200.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2012 R2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "6.3.9600.23022",
                  "status": "affected",
                  "version": "6.3.9600.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2012 R2 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "6.3.9600.23022",
                  "status": "affected",
                  "version": "6.3.9600.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.14393.8868",
                  "status": "affected",
                  "version": "10.0.14393.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2016 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.14393.8868",
                  "status": "affected",
                  "version": "10.0.14393.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.17763.8389",
                  "status": "affected",
                  "version": "10.0.17763.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2019 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.17763.8389",
                  "status": "affected",
                  "version": "10.0.17763.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2022",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.20348.4773",
                  "status": "affected",
                  "version": "10.0.20348.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.25398.2149",
                  "status": "affected",
                  "version": "10.0.25398.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2025",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.32370",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2025 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.32370",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.28000.1575",
                      "versionStartIncluding": "10.0.28000.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "10.0.28000.1575",
                      "versionStartIncluding": "10.0.28000.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                      "versionEndExcluding": "10.0.17763.8389",
                      "versionStartIncluding": "10.0.17763.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.20348.4773",
                      "versionStartIncluding": "10.0.20348.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.17763.8389",
                      "versionStartIncluding": "10.0.17763.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.17763.8389",
                      "versionStartIncluding": "10.0.17763.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.19044.6937",
                      "versionStartIncluding": "10.0.19044.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "10.0.19045.6937",
                      "versionStartIncluding": "10.0.19045.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.26100.32370",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.26200.7840",
                      "versionStartIncluding": "10.0.26200.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.22631.6649",
                      "versionStartIncluding": "10.0.22631.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "10.0.22631.6649",
                      "versionStartIncluding": "10.0.22631.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_23h2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.25398.2149",
                      "versionStartIncluding": "10.0.25398.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.26100.7840",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.26100.32370",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.14393.8868",
                      "versionStartIncluding": "10.0.14393.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                      "versionEndExcluding": "10.0.14393.8868",
                      "versionStartIncluding": "10.0.14393.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.14393.8868",
                      "versionStartIncluding": "10.0.14393.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "6.2.9200.25923",
                      "versionStartIncluding": "6.2.9200.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "6.3.9600.23022",
                      "versionStartIncluding": "6.3.9600.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "6.2.9200.25923",
                      "versionStartIncluding": "6.2.9200.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*",
                      "versionEndExcluding": "6.3.9600.23022",
                      "versionStartIncluding": "6.3.9600.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "datePublic": "2026-02-10T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en-US",
              "value": "Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en-US",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-693",
                  "description": "CWE-693: Protection Mechanism Failure",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:25:25.024Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "MSHTML Framework Security Feature Bypass Vulnerability",
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"
            }
          ],
          "title": "MSHTML Framework Security Feature Bypass Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2026-21513",
        "datePublished": "2026-02-10T17:51:26.733Z",
        "dateReserved": "2025-12-30T18:10:54.845Z",
        "dateUpdated": "2026-05-11T21:25:25.024Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }