← back
CVE-2026-21513

MSHTML Framework Security Feature Bypass Vulnerability

CVSS 8.8 HIGHEPSS 15.4%● KEVCWE-693
In short

A flaw in MSHTML Framework allows attackers to bypass a built-in security protection through a network connection. This means malicious actors could circumvent safeguards designed to protect your system.

Technical detail

A security feature bypass vulnerability in MSHTML Framework (CWE-693: Protection Mechanism Failure) permits remote attackers to circumvent protection mechanisms without authentication. The attack vector is network-based, with no user interaction required, resulting in potential compromise of the intended security controls.

Summary generated and translated by AI from the official description.
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →