A newly discovered zero-day patched by Microsoft may have been exploited by the state-backed threat actor APT28, according to recent research by Akamai.
See also: Russian hackers use Pakistani hackers' servers for attacks

The vulnerability, codenamed CVE-2026-21513 (CVSS score: 8.8), concerns a serious defense mechanism bypass in the MSHTML Framework. As Microsoft stated, this is a failure of a defense mechanism that could allow an unauthorized attacker to bypass a security feature over a network. The issue was fixed as part of the February 2026 Patch Tuesday.
The company also confirmed that the flaw had already been exploited as a zero-day in real attacks, attributing the report to the Microsoft Threat Intelligence Center (MSTIC), the Microsoft Security Response Center (MSRC), the Office Product Group Security Team , and the Google Threat Intelligence Group.
In a possible attack scenario, the attacker could convince the victim to open a malicious HTML file or a shortcut (LNK) file that is distributed via a link or an attached email. Upon opening the file, the way the browser and Windows Shell handle the content is abused, leading the operating system to execute it. Thus, the attacker can bypass protection mechanisms and potentially achieve execution of arbitrary code.
See also: Undercut: Russian Influence Campaign against Ukraine

Although Microsoft has not disclosed details about the zero-day exploitation, Akamai reported that it detected a malicious file on VirusTotal on January 30, 2026, which is linked to infrastructure attributed to APT28. The sample had previously been flagged by CERT-UA in relation to attacks by the same group that exploited another vulnerability in Microsoft Office.
According to Akamai, CVE-2026-21513 is due to the logic of the “ieframe.dll” library, which handles hyperlink navigation. Insufficient validation of the target URL allows maliciously controlled data to reach code paths that call the ShellExecuteExW, allowing execution of local or remote resources outside the browser’s expected security context.
This technique allows the bypassing of Mark-of-the-Web (MotW) and Internet Explorer's Enhanced Security Configuration (IE ESC), degrading the level of protection and ultimately facilitating the execution of malicious code outside the browser sandbox via ShellExecuteExW.
See also: Russia continues the fight against VPN use

As the company points out, although this campaign is based on malicious LNK files, the vulnerable code path can be triggered by any element that embeds MSHTML.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
