8.8

CVE-2026-21513

Warning
Media report
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login Login
Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1607 HwPlatformx64 Version < 10.0.14393.8868
MicrosoftWindows 10 1607 HwPlatformx86 Version < 10.0.14393.8868
MicrosoftWindows 10 1809 HwPlatformx64 Version < 10.0.17763.8389
MicrosoftWindows 10 1809 HwPlatformx86 Version < 10.0.17763.8389
MicrosoftWindows 10 21h2 HwPlatformarm64 Version < 10.0.19044.6937
MicrosoftWindows 10 21h2 HwPlatformx64 Version < 10.0.19044.6937
MicrosoftWindows 10 21h2 HwPlatformx86 Version < 10.0.19044.6937
MicrosoftWindows 10 22h2 HwPlatformarm64 Version < 10.0.19045.6937
MicrosoftWindows 10 22h2 HwPlatformx64 Version < 10.0.19045.6937
MicrosoftWindows 10 22h2 HwPlatformx86 Version < 10.0.19045.6937
MicrosoftWindows 11 23h2 HwPlatformarm64 Version < 10.0.22631.6649
MicrosoftWindows 11 23h2 HwPlatformx64 Version < 10.0.22631.6649
MicrosoftWindows 11 24h2 HwPlatformarm64 Version < 10.0.26100.7781
MicrosoftWindows 11 24h2 HwPlatformx64 Version < 10.0.26100.7781
MicrosoftWindows 11 25h2 HwPlatformarm64 Version < 10.0.26200.7781
MicrosoftWindows 11 25h2 HwPlatformx64 Version < 10.0.26200.7781
MicrosoftWindows Server 2016 SwEdition- HwPlatformx64 Version < 10.0.14393.8868
MicrosoftWindows Server 2019 SwEdition- HwPlatformx64 Version < 10.0.17763.8389
MicrosoftWindows Server 2022 SwEdition- HwPlatformx64 Version < 10.0.20348.4711
MicrosoftWindows Server 2022 23h2 SwEdition- HwPlatformx64 Version < 10.0.25398.2149
MicrosoftWindows Server 2025 HwPlatformx64 Version < 10.0.26100.32313

10.02.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Internet Explorer Protection Mechanism Failure Vulnerability

Vulnerability

Microsoft Internet Explorer contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

Description

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metrics
Type Source Score percentile
EPSS FIRST.org 27.97% 0.964
CVSS Metrics
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.