CVE-2026-26120Disclosure(microsoft / bing)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft bing systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bing

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
bing

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-22: 1Mentions · 2026-03-24: 2Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 103-2203-2403-26
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-242
Disclosure1General1
2026-03-261
Disclosure1
Full discourse4 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft Bing の改ざんの脆弱性 CVE-2026-26120 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26120

    Post summary

    The tweet announces Microsoft Bing tampering vulnerability CVE‑2026‑26120 and links to the Microsoft advisory, but does not provide PoC, exploit, or concrete vulnerability details.

    1010062
    88 followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 CVE-2026-26120 Security Vulnerability 影響: 改ざん 最大深刻度: 緊急 CVSS:3.1 6.5 / 5.9 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036264351963947329

    Post summary

    The tweet reports a Microsoft vulnerability (CVE-2026-26120) with severity details but indicates no public or active exploitation, yet no patches or exploitation code are discussed.

    1000029
    88 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-26120 | Microsoft Bing Tampering Vulnerability https://www.aakashrahsi.online/post/cve-2026-26120 https://t.co/3twYE3X2eA

    Post summary

    The text announces CVE‑2026‑26120 as a Microsoft Bing tampering vulnerability, but provides no PoC, exploit details, or remediation information.

    0000026
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26120 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. https://www.cve.org/CVERecord?id=CVE-2026-26120

    Post summary

    The text reports a Server‑side Request Forgery vulnerability (CVE‑2026‑26120) in Microsoft Bing that allows unauthorized network tampering, without mentioning PoC, exploit code, or a patch.

    00000186
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftbing---

Explore more