216.73.217.22

Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513

· Published 25/02/2026 11:46 · Modified 25/02/2026 11:56

Export JSON

Essential information

Published
25/02/2026 11:46
Modified
25/02/2026 11:56
Tags
2026-02-25 CVE-2026-21513 exploit ieframe.dll mshtml patchdiff-ai shellexecuteexw windows zero-day
Related entities
1 vulnerabilities (cve), 1 observables, 1 intrusion sets (apt), 2 techniques (mitre), 2 others

Description

This analysis examines , a security bypass vulnerability in Microsoft's framework, patched in February 2026. The flaw, actively exploited by Russian state-sponsored actor APT28, affects all versions and has a CVSS score of 8.8. Using , researchers identified the root cause in 's hyperlink navigation handling, allowing arbitrary file execution outside the browser's security context. The involves a crafted Shortcut file embedding HTML, communicating with APT28-linked infrastructure. It bypasses security measures like Mark of the Web and IE Enhanced Security Configuration through nested iframes and DOM manipulation, ultimately invoking for out-of-sandbox execution.

External references