Vulnerabilities & Exploits · Zero-Day Exploit

APT28 Exploited MSHTML Zero-Day Against Windows Systems

Russia-linked APT28 exploited MSHTML vulnerability CVE-2026-21513 to bypass security controls via crafted LNK and HTML files and potentially enable code execution on Windows.

1 source · Mar 2

CVE-2026-21513

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a… EPSS 16% (97th percentile). Microsoft patch: 5077179.

Patch available KB5077179 Download →

CISA federal remediation date Mar 3

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-03

Every edition of this story: APT28 Exploited MSHTML Zero-Day Against Windows Systems

More from today