Mehmet INCE[verified]@mdisecDisclosure
OpenAI’s partner XBOW announced two new RCE vulnerabilities (CVE-2026-32194 and CVE-2026-32191) affecting the Bing production server, providing basic technical details but no PoC, exploit code, patch information, or evidence of active exploitation.
Xavier Rivera[verified]@XavierRiveraXActive Exploitation
CVE-2026-32194 and CVE-2026-32191 were actively exploited via crafted SVG files on Bing’s image servers and Linux hosts, executing commands as SYSTEM/root; vulnerability patches were applied server-side in March.
The Daily Tech Feed[verified]@dailytechonxDisclosure
The post announces two new CVEs (2026‑32194, 2026‑32191) in Bing Images that allow remote code execution via crafted SVG files and notes that patches are now available.
IntegSec[verified]@integ_secDisclosure
The article announces a newly identified OS command injection vulnerability in Microsoft Bing Images and discusses its potential business impact and general response recommendations.
SecureChap[verified]@SecureChapActive Exploitation
Bing’s image pipeline was compromised via a base64‑encoded SVG that triggered command injection, allowing execution as root on Linux and SYSTEM on Windows. Microsoft issued a patch in March 2026, but the vulnerability was actively exploited before that.
dbugs[verified]@ptdbugsDisclosure
The text announces a high‑severity OS command injection vulnerability in Microsoft Bing Images (CVE‑2026‑32191) and provides technical details, but does not mention a PoC, exploit code, active exploitation, or patch.
CyberTLDR@CyberTLDRActive Exploitation
Microsoft’s Bing image search was exploited via OS command injection using a crafted SVG that executed SYSTEM commands, prompting a patch from Microsoft.
TECHEPAGES@techepagesPatch
Microsoft has patched two critical RCE vulnerabilities (CVE-2026-32194 & CVE-2026-32191) in Bing Images that allowed system‑level command injection through crafted SVG files.