CVE-2026-32194Disclosure(microsoft / bing_images)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft bing_images systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bing_images

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 11 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 21 signals
  • Disclosure: 9 classified signals
  • General: 4 classified signals
  • Peaked 4d ago at 6 mentions (2026-07-24); latest day: 1
  • 22 total mentions across 11 days

Affected systems

Vendors
Products
bing_images

1 version affected across 1 product

Deep dive

Activity timeline22 mentions / 11d
02356Mentions · 2026-03-19: 2Mentions · 2026-03-20: 3Mentions · 2026-03-23: 1Mentions · 2026-03-24: 2Mentions · 2026-03-26: 2Mentions · 2026-04-03: 1Mentions · 2026-07-24: 6Mentions · 2026-07-25: 2Mentions · 2026-07-27: 1Mentions · 2026-07-30: 1Mentions · 2026-08-22: 1PoC Mentioned / Linked · 2026-07-24: 1Active Exploitation · 2026-07-24: 2Active Exploitation · 2026-07-25: 1Active Exploitation · 2026-07-27: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-07-24: 5Patch / Workaround · 2026-07-25: 2Patch / Workaround · 2026-07-27: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 3Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-26: 2Technical Details · 2026-04-03: 1Technical Details · 2026-07-24: 6Technical Details · 2026-07-25: 1Technical Details · 2026-07-27: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-22: 103-1903-2003-2303-2403-2604-0307-2407-2507-2707-3008-22
Signal classification5 categories
Disclosure
940.9%
Patch
522.7%
General
418.2%
Active Exploitation
313.6%
Exploit
14.5%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-203
Disclosure3
2026-03-231
Patch1
2026-03-242
Disclosure1General1
2026-03-262
Disclosure1General1
2026-04-031
General1
2026-07-246
Active Exploitation2Disclosure1Patch3
2026-07-252
Active Exploitation1Patch1
2026-07-271
Exploit1
2026-07-301
Disclosure1
2026-08-221
General1
Full discourse20 posts
  • Mehmet INCE@mdisec
    Disclosure

    And OpenAI's partner XBOW disclosed two nt/authority level RCE vulnerabilities in Bing prod server,(CVE-2026-32194 and CVE-2026-32191) 😂 https://t.co/2losmW9EW5

    Post summary

    OpenAI partner XBOW disclosed two RCE vulnerabilities (CVE-2026-32194, CVE-2026-32191) affecting Bing production servers, with no indication of active exploitation, PoC, or mitigation details.

    0101513.5K
    35.2K followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    A crafted SVG ran commands as SYSTEM on Bing's production image servers, and as root on the Linux hosts in the same fleet. Two critical CVEs (CVE-2026-32194, CVE-2026-32191), CVSS 9.8 each. XBOW hid a shell command inside the SVG's image reference. Patched server-side in March.

    Post summary

    Two critical CVEs (CVE‑2026‑32194, CVE‑2026‑32191) enabled crafted SVG files to execute commands as SYSTEM/root on Bing’s image servers and Linux hosts; the vulnerability was actively exploited, and a server‑side patch was applied in March.

    03034805
    604 followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    1/3 A single crafted SVG uploaded to Bing image search ran commands as SYSTEM on Microsoft's own servers. Two OS command injection bugs (CVE-2026-32194, CVE-2026-32191) let an image reach a shell with full privileges. Microsoft has patched. #CyberSecurity #InfoSec #CVE https://t.co/6dTWAnmxN4

    Post summary

    The tweet reports that a crafted SVG was used to execute commands as SYSTEM via two command‑injection CVEs on Microsoft’s servers, and notes that Microsoft has released a patch.

    10033581
    40 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two critical RCE flaws (CVSS 9.8), CVE-2026-32194 & CVE-2026-32191, in Bing Images let attackers hijack backend servers using just a crafted SVG file — achieving SYSTEM-level access via command injection in the image-processing pipeline. Discovered by AI security researcher XBOW (now top 10 on MS's bug bounty leaderboard 👀). Already patched by Microsoft.

    Post summary

    Microsoft has patched two critical RCE flaws (CVE‑2026‑32194 & CVE‑2026‑32191) preventing command injection via crafted SVG files in Bing Images; the vulnerabilities are fully disclosed and mitigated.

    000411.3K
    38 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerabilities in Bing Images, identified as CVE-2026-32194 and CVE-2026-32191, allow remote code execution via crafted SVG files. These flaws, now patched, underscore the importance of robust input validation in image-processing pipelines to prevent command injection attacks. #Security #BingImages #RCE #Cybersecurity #Microsoft #Vulnerabilities https://thedailytechfeed.com/critical-vulnerabilities-in-bing-images-allow-remote-code-execution/

    Post summary

    The tweet reports that Microsoft has patched CVE-2026-32194 and CVE-2026-32191, which allow RCE through crafted SVG files, stressing the need for better input validation.

    00023215
    710 followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ Microsoft fixed Bing Images flaws where a booby-trapped upload could trigger SYSTEM-level code execution. No user action needed—just upload an image and let the cloud do the dangerous part. https://windowsforum.com/threads/cve-2026-32194-bing-images-rce-fixed-server-side-no-user-action.440305/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #RemoteCodeExecution #CloudSecurity #Imagemagick #BingImages https://t.co/dX4uWilQ4F

    Post summary

    Microsoft has fixed a CVE‑2026‑32194 in Bing Images that allowed SYSTEM‑level code execution via a booby‑trapped image upload, with no user action required.

    0201175
    1.3K followersView on X
  • Jim Nitterauer 🇺🇸@JNitterauer
    Exploit

    XBOW's autonomous offensive AI got code exec as SYSTEM on Bing's image servers with a crafted SVG (CVE-2026-32194/32191, both 9.8). Microsoft fixed it server-side. AI bug hunting is scaling. https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html #cybersecurity #AIsecurity

    Post summary

    Xbow's autonomous AI demonstrated SYSTEM‑level code execution on Bing’s image servers via crafted SVGs, showcasing a high‑severity CVE that Microsoft has since patched.

    00110312
    8.5K followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft Bing Images Remote Code Execution Vulnerability CVE-2026-32194 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32194

    Post summary

    This tweet announces Microsoft Bing Images Remote Code Execution Vulnerability (CVE‑2026‑32194) and links to Microsoft’s official page, but does not detail PoC, exploitation, or patch information.

    1010099
    88 followersView on X
  • Nico Waisman@nicowaisman
    General

    @AndrewMohawk This one CVE-2026-32194 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32194), is even more interesting because in an authenticated remote code execution that will give you a SYSTEM shell

    Post summary

    The tweet cites CVE‑2026‑32194 as an authenticated RCE providing a SYSTEM shell and links to Microsoft’s vulnerability page, but offers no PoC, exploit, patch, or evidence of active exploitation.

    10000212
    13.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-32194: Microsoft Bing Images Command Injection Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04tWWJW0

    Post summary

    The brief headline references CVE‑2026‑32194 as a command injection flaw in Microsoft Bing Images but provides no further technical, exploitation, or mitigation details.

    0000027
    33 followersView on X
  • Beto Day@BetoDay
    Patch

    ⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE #Infosec https://t.co/DhvxeyEdKM

    Post summary

    The tweet announces critical code‑execution vulnerabilities affecting Microsoft Bing and image products, and confirms that official patches are available.

    0000084
    200 followersView on X
  • SecureChap@SecureChap
    Disclosure

    A base64 SVG in the imageBin field reached Bing's /images/kblob endpoint and executed commands as root. XBOW disclosed two unauthenticated command-injection flaws in the image pipeline. CVE-2026-32194 affected the public Search by Image path. CVE-2026-32191 affected the crawler path via an attacker-controlled imgurl fetched by bingbot/2.0. Both routes fed the same conversion logic. The SVG referenced an external image whose href began with a pipe. ImageMagick treated the reference as a delegate shell command during rasterization because the worker's policy.xml left delegates unrestricted. A one-pixel PoC ran a command on the worker and curled the output back. Linux hosts returned uid=0. Windows Server 2022 hosts ran as NT AUTHORITY\SYSTEM with SeImpersonatePrivilege enabled. Microsoft patched server-side in March 2026. The writeup appeared July 23. The same ImageMagick delegate pattern that failed in 2016 still reached production image fleets when policy files stayed permissive.

    Post summary

    Bing’s image pipeline has two unauthenticated command‑injection CVEs (CVE-2026-32194/32191). A one‑pixel PoC demonstrates root execution, and Microsoft has released a patch in March 2026.

    0000088
    164 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited crafted SVG files to achieve command injection in Microsoft Bing Images (CVE-2026-32194), escalating to SYSTEM privileges on Windows and root access on Linux servers. This level of access enables lateral movement within cloud infrastructure, where runtime segmentation could help contain post-compromise activity. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsofts-servers-cve-2026-32194

    Post summary

    A malicious PNG exploitation of CVE-2026-32194 is actively occurring, allowing attackers to gain SYSTEM/root privileges on Microsoft Bing Images servers and move laterally within cloud infrastructures.

    0000067
    1.9K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-32194 | Microsoft Bing Images Remote Code Execution Vulnerability https://www.aakashrahsi.online/post/cve-2026-32194 https://t.co/CY7ta99tu8

    Post summary

    A newly announced CVE (2026-32194) targeting Microsoft Bing Images is identified as a remote code execution vulnerability, but no PoC, exploitation or patch details are shared.

    0000042
    1 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-32194 | Microsoft Bing Images Remote Code Execution Vulnerability https://www.aakashrahsi.online/post/cve-2026-32194 https://t.co/jW43jNv91m

    Post summary

    The tweet links to a post announcing CVE‑2026‑32194, a remote code execution issue in Microsoft Bing Images, but provides no additional details about exploitation, patches or active use.

    0000047
    1 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-32194 Security Vulnerability 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 9.8 / 8.5 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036271263350677706

    Post summary

    The tweet declares the existence of CVE-2026-32194, a remote code execution vulnerability with high CVSS scores, but provides no exploit, patch, or active exploitation details.

    0000051
    88 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address a Remote Code Execution Vulnerability in Microsoft Bing Images. #CVE-2026-32194 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32194

    Post summary

    Microsoft issued a security update for CVE-2026-32194 that resolves a remote code execution flaw in Bing Images, with no proof of concept or exploit disclosed.

    00000112
    8.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32194 Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a ne… https://www.cve.org/CVERecord?id=CVE-2026-32194 ----- Traducción: CVE-2026-32194 Neu… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-32194, a command injection vulnerability in Microsoft Bing Images, providing a brief technical description but no PoC, exploit code, or patch information.

    0000049
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32194 Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a ne… https://www.cve.org/CVERecord?id=CVE-2026-32194

    Post summary

    The post cites CVE‑2026‑32194, a command injection flaw in Microsoft Bing Images that could allow unauthorized code execution, but no PoC, exploit, patch, or active exploitation details are provided.

    00000246
    56.8K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Microsoft Bing Images Remote Code Execution Vulnerability CVE: CVE-2026-32194 Vendor: Microsoft Product: Microsoft Bing Images CVSS: 9.8 Credits: n/a Description: Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-32194 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32194 #dbugs_vuln

    Post summary

    A high‑severity command injection vulnerability, CVE‑2026‑32194, has been disclosed for Microsoft Bing Images with CVSS 9.8, citing vendor advisory references but no PoC, exploit, or patch details.

    0000050
    649 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftbing_images---

Explore more