{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T13:59:12.748","vulnerabilities":[{"cve":{"id":"CVE-2026-21513","sourceIdentifier":"secure@microsoft.com","published":"2026-02-10T18:16:33.643","lastModified":"2026-03-30T13:28:07.120","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network."},{"lang":"es","value":"Falla del mecanismo de protección en el framework MSHTML permite a un atacante no autorizado eludir una característica de seguridad a través de una red."}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"cisaExploitAdd":"2026-02-10","cisaActionDue":"2026-03-03","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability","weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-693"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.14393.8868","matchCriteriaId":"E78A20FD-B910-43DF-BE89-E971E2FD0049"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.14393.8868","matchCriteriaId":"B941280B-97F6-4F60-80A3-40482A74488D"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.17763.8389","matchCriteriaId":"C09C54DA-6AB0-4696-A2F2-C11CFC292EA9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.17763.8389","matchCriteriaId":"369B4E41-3895-4CB7-BD37-D2E4A4D52FB9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19044.6937","matchCriteriaId":"EDB3FD9A-2786-4EC1-8989-2B0D054E0307"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19044.6937","matchCriteriaId":"893DBA65-116B-4AE0-80E1-50458CB5FDAD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19044.6937","matchCriteriaId":"37E2BFF1-28C0-4FA0-9A6C-020146E4AD54"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19045.6937","matchCriteriaId":"3ABF7E9C-769A-4330-AD97-FE3CD766E577"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19045.6937","matchCriteriaId":"F54B0C64-9A1F-470B-9824-322CF362507F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19045.6937","matchCriteriaId":"A5BD3F0C-1E6F-4937-806C-B87CA19C2830"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22631.6649","matchCriteriaId":"B273EF5A-3157-4842-AE91-CEC289813902"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22631.6649","matchCriteriaId":"CD2513FC-D399-4DBF-921F-13B4D1497127"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.7781","matchCriteriaId":"B08450A0-0F7E-4A05-8989-900221992766"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.7781","matchCriteriaId":"9D30B348-DAE7-43EC-85FA-38E1715258A9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.7781","matchCriteriaId":"8F23FFCF-9C69-4D27-AF21-D09A6041AA3A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.7781","matchCriteriaId":"D1D93202-BDDB-438F-934E-1FE904B3651B"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*","versionEndExcluding":"10.0.14393.8868","matchCriteriaId":"C9801763-02E0-471B-A571-6E9733A5358D"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*","versionEndExcluding":"10.0.17763.8389","matchCriteriaId":"5D132B4B-F718-420D-B31D-39390ADB6ABB"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:-:*:x64:*","versionEndExcluding":"10.0.20348.4711","matchCriteriaId":"E1DDF720-A228-412B-BF01-ECD759C35A24"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:-:*:x64:*","versionEndExcluding":"10.0.25398.2149","matchCriteriaId":"40F60E69-9FF7-4613-84D3-1982F357A82E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.32313","matchCriteriaId":"62BDF24B-B74A-4F48-A6A5-CA375ECE9B5C"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-21513-detection-script-security-feature-bypass-vulnerability-in-mshtml-framework","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-21513-mitigation-script-security-feature-bypass-vulnerability-in-mshtml-framework","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21513","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}}]}