HIGH
CVE-2026-21513
CVSS
8.8
KEV
Description
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Summary dbcve.org
A protection mechanism failure in the MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. This is a security feature bypass vulnerability in Microsoft's HTML rendering engine used in legacy browsers and components.
Mitigation
Apply Microsoft security updates for MSHTML when available; monitor vendor advisories. Implement network-level filtering and restrict exposure of affected systems until patches are deployed.
Weakness (CWE)
CWE-693
EPSS Score
15.64%
Probability of exploitation in next 30 days
96.7th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-21513-detection-script-security-feature-bypass-vulnerability-in-mshtml-framework
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-21513-mitigation-script-security-feature-bypass-vulnerability-in-mshtml-framework
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21513
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.