CISA KEV · catalog date Feb 10, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2026-21513
MSHTML Framework Security Feature Bypass Vulnerability
Exploited in the wild (CISA KEV since Feb 10, 2026). microsoft reports CVSS 3.1 8.8. EPSS estimates 15.4% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- State
- PUBLISHED
- Published
- Feb 10, 2026
- Updated
- May 11, 2026
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: MSHTML Framework Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- MSHTML Framework Security Feature Bypass Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 15.38% probability · 96.53th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.153840000000; percentile 0.965270000000
FIRST EPSS · score date Aug 27, 2026 · 96.5th percentile · first observed Aug 27, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
MSHTML Framework Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- MSHTML Framework Security Feature Bypass Vulnerability
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
15.38% probability · 96.53th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.153840000000; percentile 0.965270000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
35 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.8868", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.8389", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19044.0", "lessThan": "10.0.19044.6937", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19045.0", "lessThan": "10.0.19045.6937", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.6649", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.6649", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.7840", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26200.0", "lessThan": "10.0.26200.7840", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.28000.0", "lessThan": "10.0.28000.1575", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.28000.0", "lessThan": "10.0.28000.1575", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25923", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.23022", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.23022", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25923", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.8868", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.8868", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.8389", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.8389", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.20348.0", "lessThan": "10.0.20348.4773", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.25398.0", "lessThan": "10.0.25398.2149", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.32370", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.32370", "versionType": "custom"}]product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.0.14393.8868
- Match ID
b941280b-97f6-4f60-80a3-40482a74488d
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.14393.8868
- Match ID
e78a20fd-b910-43df-be89-e971e2fd0049
product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43Linked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.8389
- Match ID
369b4e41-3895-4cb7-bd37-d2e4a4d52fb9
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.8389
- Match ID
c09c54da-6ab0-4696-a2f2-c11cfc292ea9
product-ec10c9f400f23fdf118887f60fe116ffde4adb76dcf118cdd3a7556fd033da3bLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- through excluding 10.0.19044.6937
- Match ID
893dba65-116b-4ae0-80e1-50458cb5fdad
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- through excluding 10.0.19044.6937
- Match ID
37e2bff1-28c0-4fa0-9a6c-020146e4ad54
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- through excluding 10.0.19044.6937
- Match ID
edb3fd9a-2786-4ec1-8989-2b0d054e0307
Affected-product evidence
Accepted scope and product mapping
13 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-026201767813843a6d53867bacde4a55c3035cb868c0a72434012c5e30dab148
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07c05cbc-d071-4945-895f-852ae012f8d673adf85d-3ee7-4b3e-9f43-c5296b480e9cvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b351fa0b-6f44-4c4e-aeec-dedb763288efvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-25a2932c0bbcb648f7e391c8b9d34c734e5085444c03c1c206b9d4c4baa80b25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c05a2f4-3576-495f-8444-5f5302ecb55fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-3fe7da0d567cbba9da3f09deea827ccacd90ac3643fc3e1622f75fb001f24443
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6476b8ad-569d-406c-8fec-378ddf88a054vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6f8b56e1-0717-44f6-9b27-3e91256933a470c395e3-646b-4238-b599-d3a0413ca275vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
167bc8ca-e44f-487b-9c2a-319c14b9ecf63741c2cc-67ef-475c-bc3d-02923f0af215vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-8665879a2f5fe8b8eab868c43d6ace340b95d1f3879639d97ebdf60ef7b49b5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
62b96c6b-122f-4ca4-9050-dd3e44d0071d8b9f08d6-add1-4e89-9a39-7f304f517767vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
81107b0e-a5d4-4ddf-a6aa-fbeeeed339fdb89f7404-d461-42e0-8e5f-2741f1fb290fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a6295b9daad3ca57ce70751badba5b7fe99229c8a562cc7400e8cfef3daccaee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1947df54-7a6f-4f50-a7e5-2a57176b51204ad7e7c4-9f82-4cff-a0e2-7feb6d36523369c7c9c3-c44f-4bb2-ac04-d52c28a504d8vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-bc66b50eed682b3633d0f3a2914725d0a72d6d0d5fece14f566d91bc87448c0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1f2d61bb-fcaf-433a-92ae-a51f6fb371e4vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d196d31962e613955a91e33e795c22dcfa7bf25173abebaca616a6350cce9ce1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a7bec7b7-d8b9-4a5a-a534-aa032621144fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-e9349aae7bae97a590ecc61309b626fd2c236f349da7ff6c765ab3d5cefdfa78
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
17981eb9-0ea2-4182-ab41-0bb49f2326fe32632b40-9f3b-454f-98f2-6006951b43c9vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-ec10c9f400f23fdf118887f60fe116ffde4adb76dcf118cdd3a7556fd033da3b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
78d46809-bb78-4dc0-9506-a0e144464ce79ab71778-00f8-42fe-89b7-9311c7dae1ceb2afbe84-1c64-4f35-b5e8-62c6f44870c4Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 22
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
03588b37-469b-4de3-ad7c-cba12eee9e351882bbb5-ff17-4d77-89cd-d44aed6ce28f23ee4b83-41c8-4a42-a2a8-1d8112ac12922eeef6f1-7ad8-4f5b-a41e-cba498278d683057c306-3932-4773-99ff-e2623b66408832996dc3-f748-42a6-b4d3-00a2bad4cec43473b448-dbe8-4f35-b540-3cb52b25b1574be0fa24-8500-4528-b868-77fc96045c1c560cdcec-69ed-41c4-aa3e-688eaf6c319a58dca740-fb1e-48b1-80ed-8f2a4c44d7105a2e2923-86f2-4f0e-a0b5-2c6a9bffaa546b53683d-7d39-4796-87f0-11733cafb7816f0db9ac-7a43-4d77-aadc-e9ada87009a2861fc647-346c-4756-a5f9-8739e062935697899cd0-f860-46ba-9e1e-e30cdddeeb8f9978d02f-59ec-465b-a93b-ebef5151ccd7a01dba41-9291-466b-9798-ac26b044067fa9642618-59a4-4d38-bc9c-b4adf9638820aa5f4ef2-fd17-416a-a175-a2ff81f235c1bf01533c-21c8-464d-888b-7588d84fcccfec89c868-1c68-4af8-b70d-25fa8f1d2fd5eed43a22-8171-42dc-b2a4-c26e28b54725Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.