Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update

Microsoft has released its Patch Tuesday updates, addressing 59 vulnerabilities, including a critical zero-day flaw in the Windows MSHTML framework.

Microsoft has released its Patch Tuesday updates, addressing 59 vulnerabilities, including a critical zero-day flaw in the Windows MSHTML framework.

The identified vulnerability is tracked as CVE-2026-21513, which allows attackers to bypass security features and execute arbitrary code. The flaw is actively being exploited by APT28, a known advanced persistent threat group.

Feature Details

CVE ID CVE-2026-21513

CVSS Score 8.8 (High)

Vulnerability Type Security Feature Bypass

Microsoft has released its Patch Tuesday updates, addressing 59 vulnerabilities, including a critical zero-day flaw in the Windows MSHTML framework.
Sam Quinlan · Thehackingpost

Affected Component MSHTML Framework ( ieframe.dll )

Threat Actor APT28 (Russian State-Sponsored)

Exploitation Status Actively Exploited In-the-Wild

The vulnerability is located in the ieframe.dll component, which manages hyperlink navigation for Internet Explorer. The code lacked proper validation for target URLs, allowing attackers to send malicious inputs to specific code paths that trigger the ShellExecuteExW function. This flaw allows threat actors to escape the browser's secure sandbox environment and execute arbitrary local or remote files on the victim's machine without warning.

Advertisement

Researchers identified that APT28 was using this vulnerability in late January 2026. The exploit involved a Windows Shortcut file ( .lnk ) with a hidden HTML payload connecting to an attacker-controlled domain to retrieve multistage malware. The attack leveraged nested iframes and multiple Document Object Model (DOM) contexts to bypass Windows security defenses, such as Mark of the Web (MotW) and Internet Explorer Enhanced Security Configuration (IE ESC).

While the observed campaign primarily used malicious .lnk files, experts caution that other applications embedding the MSHTML component could also trigger the vulnerability. As a result, various delivery methods beyond traditional phishing are possible.

In response, Microsoft introduced stricter hyperlink protocol validation in the February 2026 security patch update. This fix ensures that standard protocols such as HTTP, HTTPS, and FILE are contained and executed within the secure browser environment, preventing them from being passed directly to the ShellExecuteExW function, thus neutralizing the exploit chain.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories