CVE-2026-21513
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Critical vulnerabilities, curated daily for security professionals
Monday's vulnerability disclosures reveal 3 critical-severity flaws affecting Changing IDExpert Windows Logon Agent and e-Excellence U-Office Force, all scoring CVSS 9.8. Critical CVE count rose from 0 to 3 compared to the prior day, while high-priority vulnerabilities dropped 57% from 35 to 15. CVE-2026-2999 and CVE-2026-3000 target Changing IDExpert's Windows Logon Agent, and CVE-2026-3422 impacts e-Excellence U-Office Force, each enabling potential remote code execution or authentication bypass. Active exploitation spans 17 vulnerabilities across Microsoft Windows, Microsoft Office, Apple OS, Google Chromium, GitLab, Roundcube Webmail, and Notepad++, indicating broad targeting of enterprise infrastructure and productivity tools. No patches are currently available for the newly disclosed CVEs, requiring organizations to prioritize compensating controls and monitoring.
Immediate action: Prioritize review of Changing IDExpert Windows Logon Agent and e-Excellence U-Office Force deployments, applying network segmentation and access restrictions until patches are released. Monitor for exploitation activity targeting Microsoft Windows, Apple OS, Google Chromium, and Roundcube Webmail, and apply any available vendor mitigations for the 17 actively exploited vulnerabilities.
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.