Mehmet INCE[verified]@mdisecDisclosure
OpenAI partner XBOW disclosed two RCE vulnerabilities (CVE-2026-32194, CVE-2026-32191) affecting Bing production servers, with no indication of active exploitation, PoC, or mitigation details.
Xavier Rivera[verified]@XavierRiveraXActive Exploitation
Two critical CVEs (CVE‑2026‑32194, CVE‑2026‑32191) enabled crafted SVG files to execute commands as SYSTEM/root on Bing’s image servers and Linux hosts; the vulnerability was actively exploited, and a server‑side patch was applied in March.
The Daily Tech Feed[verified]@dailytechonxPatch
The tweet reports that Microsoft has patched CVE-2026-32194 and CVE-2026-32191, which allow RCE through crafted SVG files, stressing the need for better input validation.
Windows Forum[verified]@windowsforumPatch
Microsoft has fixed a CVE‑2026‑32194 in Bing Images that allowed SYSTEM‑level code execution via a booby‑trapped image upload, with no user action required.
Nico Waisman[verified]@nicowaismanGeneral
The tweet cites CVE‑2026‑32194 as an authenticated RCE providing a SYSTEM shell and links to Microsoft’s vulnerability page, but offers no PoC, exploit, patch, or evidence of active exploitation.
IntegSec[verified]@integ_secGeneral
The brief headline references CVE‑2026‑32194 as a command injection flaw in Microsoft Bing Images but provides no further technical, exploitation, or mitigation details.
SecureChap[verified]@SecureChapDisclosure
Bing’s image pipeline has two unauthenticated command‑injection CVEs (CVE-2026-32194/32191). A one‑pixel PoC demonstrates root execution, and Microsoft has released a patch in March 2026.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
A malicious PNG exploitation of CVE-2026-32194 is actively occurring, allowing attackers to gain SYSTEM/root privileges on Microsoft Bing Images servers and move laterally within cloud infrastructures.