CVE-2026-21513
Known exploited · CISA KEV
CVSS 8.8 HIGH: protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a… EPSS 16% (97th percentile). Microsoft patch: 5077179.
Patch available KB5077179 Download →
CISA federal remediation date Mar 3