HIGH

CVE-2026-21513

Microsoft Windows 10 1607 2026-02-10 CVSS v3.1
CVSS
8.8
KEV

Description

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Summary dbcve.org

A protection mechanism failure in the MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. This is a security feature bypass vulnerability in Microsoft's HTML rendering engine used in legacy browsers and components.

Mitigation

Apply Microsoft security updates for MSHTML when available; monitor vendor advisories. Implement network-level filtering and restrict exposure of affected systems until patches are deployed.

Weakness (CWE)

CWE-693

EPSS Score

15.64%
Probability of exploitation in next 30 days
96.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE