CVE-2026-21513: listed in the CISA KEV catalog
CVE-2026-21513 · CVSS 8.8 HIGH · EPSS 16% · KEV 2026-02-10 · patch available
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Is CVE-2026-21513 exploited?
- Listed in the CISA KEV catalog on 2026-02-10.
- Federal remediation due 2026-03-03.
- Past that date by 211 days.
- EPSS puts exploitation in the next 30 days at 16%.
- Public exploit code: none found in monitored sources.
Which products and versions are affected?
- Microsoft · Windows 10 Version 1607 · >= 10.0.14393.0, < 10.0.14393.8868
- Microsoft · Windows 10 Version 1809 · >= 10.0.17763.0, < 10.0.17763.8389
- Microsoft · Windows 10 Version 21H2 · >= 10.0.19044.0, < 10.0.19044.6937
- Microsoft · Windows 10 Version 22H2 · >= 10.0.19045.0, < 10.0.19045.6937
- Microsoft · Windows 11 version 22H3 · >= 10.0.22631.0, < 10.0.22631.6649
- Microsoft · Windows 11 Version 23H2 · >= 10.0.22631.0, < 10.0.22631.6649
- Microsoft · Windows 11 Version 24H2 · >= 10.0.26100.0, < 10.0.26100.7840
- Microsoft · Windows 11 Version 25H2 · >= 10.0.26200.0, < 10.0.26200.7840
- Microsoft · Windows 11 version 26H1 · >= 10.0.28000.0, < 10.0.28000.1575
- Microsoft · Windows Server 2012 · >= 6.2.9200.0, < 6.2.9200.25923
- Microsoft · Windows Server 2012 (Server Core installation) · >= 6.2.9200.0, < 6.2.9200.25923
- Microsoft · Windows Server 2012 R2 · >= 6.3.9600.0, < 6.3.9600.23022
- Microsoft · Windows Server 2012 R2 (Server Core installation) · >= 6.3.9600.0, < 6.3.9600.23022
- Microsoft · Windows Server 2016 · >= 10.0.14393.0, < 10.0.14393.8868
- Microsoft · Windows Server 2016 (Server Core installation) · >= 10.0.14393.0, < 10.0.14393.8868
- Microsoft · Windows Server 2019 · >= 10.0.17763.0, < 10.0.17763.8389
- Microsoft · Windows Server 2019 (Server Core installation) · >= 10.0.17763.0, < 10.0.17763.8389
- Microsoft · Windows Server 2022 · >= 10.0.20348.0, < 10.0.20348.4773
- Microsoft · Windows Server 2022, 23H2 Edition (Server Core installation) · >= 10.0.25398.0, < 10.0.25398.2149
- Microsoft · Windows 11 Version 26H1 for ARM64-based Systems · < 10.0.28000.1575
- Microsoft · Windows 11 version 26H1 for x64-based Systems · < 10.0.28000.1575
- Microsoft · Windows 10 Version 1809 for 32-bit Systems · < 10.0.17763.8389
- Microsoft · Windows 10 Version 1809 for x64-based Systems · < 10.0.17763.8389
- Microsoft · Windows Server 2022 (Server Core installation) · < 10.0.20348.4773, < 10.0.20348.4711
- Microsoft · Windows 10 Version 21H2 for 32-bit Systems · < 10.0.19044.6937
- Microsoft · Windows 10 Version 21H2 for ARM64-based Systems · < 10.0.19044.6937
- Microsoft · Windows 10 Version 21H2 for x64-based Systems · < 10.0.19044.6937
- Microsoft · Windows Server 2025 · < 10.0.26100.32370, < 10.0.26100.32313
- Microsoft · Windows Server 2025 (Server Core installation) · < 10.0.26100.32370, < 10.0.26100.32313
- Microsoft · Windows 11 Version 25H2 for ARM64-based Systems · < 10.0.26200.7840, < 10.0.26200.7781
- Microsoft · Windows 11 Version 25H2 for x64-based Systems · < 10.0.26200.7840, < 10.0.26200.7781
- Microsoft · Windows 11 Version 23H2 for ARM64-based Systems · < 10.0.22631.6649
- Microsoft · Windows 11 Version 23H2 for x64-based Systems · < 10.0.22631.6649
Is there a patch?
What PlainSec published about CVE-2026-21513
Primary sources
KEV and EPSS are re-checked daily. Record last updated 2026-09-09.