CVE-2026-32191Disclosure(microsoft / bing_images)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft bing_images systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bing_images

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 9 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 10 classified signals
  • Peaked 3d ago at 4 mentions (2026-07-24); latest day: 1
  • 16 total mentions across 9 days

Affected systems

Vendors
Products
bing_images

1 version affected across 1 product

Deep dive

Activity timeline16 mentions / 9d
01234Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 2Mentions · 2026-07-24: 4Mentions · 2026-07-25: 2Mentions · 2026-07-30: 1Mentions · 2026-08-22: 1PoC Mentioned / Linked · 2026-07-24: 1PoC Mentioned / Linked · 2026-07-25: 1Exploit Tool / Code · 2026-07-24: 1Active Exploitation · 2026-07-24: 2Active Exploitation · 2026-07-25: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-07-24: 4Patch / Workaround · 2026-07-25: 2Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 2Technical Details · 2026-07-24: 4Technical Details · 2026-07-25: 2Technical Details · 2026-07-30: 1Technical Details · 2026-08-22: 103-1903-2003-2203-2303-2407-2407-2507-3008-22
Signal classification3 categories
Disclosure
1062.5%
Patch
318.8%
Active Exploitation
318.8%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-201
Disclosure1
2026-03-222
Disclosure2
2026-03-231
Patch1
2026-03-242
Disclosure2
2026-07-244
Active Exploitation2Disclosure1Patch1
2026-07-252
Active Exploitation1Patch1
2026-07-301
Disclosure1
2026-08-221
Disclosure1
Full discourse16 posts
  • Mehmet INCE@mdisec
    Disclosure

    And OpenAI's partner XBOW disclosed two nt/authority level RCE vulnerabilities in Bing prod server,(CVE-2026-32194 and CVE-2026-32191) 😂 https://t.co/2losmW9EW5

    Post summary

    OpenAI’s partner XBOW announced two new RCE vulnerabilities (CVE-2026-32194 and CVE-2026-32191) affecting the Bing production server, providing basic technical details but no PoC, exploit code, patch information, or evidence of active exploitation.

    0101513.5K
    35.2K followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    A crafted SVG ran commands as SYSTEM on Bing's production image servers, and as root on the Linux hosts in the same fleet. Two critical CVEs (CVE-2026-32194, CVE-2026-32191), CVSS 9.8 each. XBOW hid a shell command inside the SVG's image reference. Patched server-side in March.

    Post summary

    CVE-2026-32194 and CVE-2026-32191 were actively exploited via crafted SVG files on Bing’s image servers and Linux hosts, executing commands as SYSTEM/root; vulnerability patches were applied server-side in March.

    03034805
    604 followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    1/3 A single crafted SVG uploaded to Bing image search ran commands as SYSTEM on Microsoft's own servers. Two OS command injection bugs (CVE-2026-32194, CVE-2026-32191) let an image reach a shell with full privileges. Microsoft has patched. #CyberSecurity #InfoSec #CVE https://t.co/6dTWAnmxN4

    Post summary

    Microsoft’s Bing image search was exploited via OS command injection using a crafted SVG that executed SYSTEM commands, prompting a patch from Microsoft.

    10033581
    40 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two critical RCE flaws (CVSS 9.8), CVE-2026-32194 & CVE-2026-32191, in Bing Images let attackers hijack backend servers using just a crafted SVG file — achieving SYSTEM-level access via command injection in the image-processing pipeline. Discovered by AI security researcher XBOW (now top 10 on MS's bug bounty leaderboard 👀). Already patched by Microsoft.

    Post summary

    Microsoft has patched two critical RCE vulnerabilities (CVE-2026-32194 & CVE-2026-32191) in Bing Images that allowed system‑level command injection through crafted SVG files.

    000411.3K
    38 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical vulnerabilities in Bing Images, identified as CVE-2026-32194 and CVE-2026-32191, allow remote code execution via crafted SVG files. These flaws, now patched, underscore the importance of robust input validation in image-processing pipelines to prevent command injection attacks. #Security #BingImages #RCE #Cybersecurity #Microsoft #Vulnerabilities https://thedailytechfeed.com/critical-vulnerabilities-in-bing-images-allow-remote-code-execution/

    Post summary

    The post announces two new CVEs (2026‑32194, 2026‑32191) in Bing Images that allow remote code execution via crafted SVG files and notes that patches are now available.

    00023215
    710 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft Bing Images Remote Code Execution Vulnerability CVE-2026-32191 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32191

    Post summary

    The post announces Microsoft’s release noting a Remote Code Execution vulnerability (CVE-2026-32191) without mentioning PoC, exploit code, or patch details.

    1010096
    88 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-32191 Security Vulnerability 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 9.8 / 8.5 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036268966935736436

    Post summary

    A new CVE-2026-32191 vulnerability that allows remote code execution has been disclosed, with high CVSS scores, but no PoC, exploit, or active exploitation has been reported.

    1000051
    88 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-32191: Microsoft Bing Images OS Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04tX4850

    Post summary

    The article announces a newly identified OS command injection vulnerability in Microsoft Bing Images and discusses its potential business impact and general response recommendations.

    0000025
    33 followersView on X
  • Beto Day@BetoDay
    Patch

    ⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE #Infosec https://t.co/DhvxeyEdKM

    Post summary

    The tweet alerts about critical code‑execution CVEs affecting Microsoft Bing and images, and announces that official patches are available.

    0000084
    200 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    A base64 SVG in the imageBin field reached Bing's /images/kblob endpoint and executed commands as root. XBOW disclosed two unauthenticated command-injection flaws in the image pipeline. CVE-2026-32194 affected the public Search by Image path. CVE-2026-32191 affected the crawler path via an attacker-controlled imgurl fetched by bingbot/2.0. Both routes fed the same conversion logic. The SVG referenced an external image whose href began with a pipe. ImageMagick treated the reference as a delegate shell command during rasterization because the worker's policy.xml left delegates unrestricted. A one-pixel PoC ran a command on the worker and curled the output back. Linux hosts returned uid=0. Windows Server 2022 hosts ran as NT AUTHORITY\SYSTEM with SeImpersonatePrivilege enabled. Microsoft patched server-side in March 2026. The writeup appeared July 23. The same ImageMagick delegate pattern that failed in 2016 still reached production image fleets when policy files stayed permissive.

    Post summary

    Bing’s image pipeline was compromised via a base64‑encoded SVG that triggered command injection, allowing execution as root on Linux and SYSTEM on Windows. Microsoft issued a patch in March 2026, but the vulnerability was actively exploited before that.

    0000088
    164 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address a Remote Code Execution Vulnerability in Microsoft Bing Images. #CVE-2026-32191 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32191

    Post summary

    Microsoft issued a security update for CVE‑2026‑32191, which is a Remote Code Execution flaw in Bing Images.

    00000119
    8.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code ov… https://www.cve.org/CVERecord?id=CVE-2026-32191 ----- Traducción: CVE-2026-32191 Neu… http://infoflow.cloud`

    Post summary

    A new CVE-2026-32191 is disclosed, describing an os command injection in Microsoft Bing Images that permits code execution; no PoC, exploit, or patch details are reported.

    0000033
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code ov… https://www.cve.org/CVERecord?id=CVE-2026-32191

    Post summary

    The post announces CVE-2026-32191, an OS command injection flaw in Microsoft Bing Images that permits code execution, with no mention of exploitation, PoC, or patch availability.

    00000234
    56.8K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Microsoft Bing Images Remote Code Execution Vulnerability CVE: CVE-2026-32191 PT-Identifier: PT-2026-26364 Vendor: Microsoft Product: Microsoft Bing Images CVSS: 9.8 Credits: n/a Description: Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-32191 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32191 #dbugs_vuln

    Post summary

    The text announces a high‑severity OS command injection vulnerability in Microsoft Bing Images (CVE‑2026‑32191) and provides technical details, but does not mention a PoC, exploit code, active exploitation, or patch.

    0000061
    649 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32191: CRITICAL] Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.#cve,CVE-2026-32191,#cybersecurity https://cvefind.com/CVE-2026-32191

    Post summary

    The post announces a critical OS command injection vulnerability in Microsoft Bing Images (CVE-2026-32191), describing the flaw but providing no PoC, exploit code, active exploitation, or patch information.

    0000066
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32191 - Critical Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-32191/ https://t.co/6LwrLZn8Il

    Post summary

    The tweet announces a critical OS command injection vulnerability in Microsoft Bing Images, providing basic technical details but no evidence of active exploitation, PoC, or patch.

    0000056
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftbing_images---

Explore more