CVE-2026-33819Disclosure(microsoft / bing)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch microsoft bing systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bing

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-24); latest day: 4
  • 12 total mentions across 4 days

Affected systems

Vendors
Products
bing

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 4d
01345Mentions · 2026-04-24: 5Mentions · 2026-04-25: 1Mentions · 2026-04-27: 2Mentions · 2026-05-12: 4Active Exploitation · 2026-04-24: 1Patch / Workaround · 2026-04-24: 2Technical Details · 2026-04-24: 3Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 2Technical Details · 2026-05-12: 304-2404-2504-2705-12
Signal classification4 categories
Disclosure
758.3%
General
325.0%
Active Exploitation
18.3%
Patch
18.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-245
Active Exploitation1Disclosure2General1Patch1
2026-04-251
Disclosure1
2026-04-272
Disclosure2
2026-05-124
Disclosure2General2
Full discourse12 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 4.23 Microsoft Bing のリモートでコードが実行される脆弱性 CVE-2026-33819 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33819

    Post summary

    Microsoft has announced a new remote code execution vulnerability in Bing (CVE‑2026‑33819) with a security advisory link, but no PoC, exploitation data, or patch information is provided.

    10100199
    85 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-33819 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical vulnerability CVE-2026-33819 with a CVSS 10 rating was disclosed, but no PoC, exploit, or patch information is provided.

    1000043
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-33819 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

    Post summary

    An advisory discloses CVE-2026-33819, a critical Microsoft Bing deserialization flaw that allows remote code execution.

    1000059
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-33819 (CVSS 10) — microsoft bing. CVE: CVE-2026-33819 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a new critical vulnerability, CVE‑2026‑33819, with a CVSS score of 10 but provides no proof of concept, exploit details, patch, or evidence of active exploitation.

    1000056
    210 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-33819 「…するために、お客様が取るべきアクションはありません」 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 10.0 / 8.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment:対象外 https://x.com/kawn2020/status/2048692187622473771

    Post summary

    CVE-2026-33819 is a remote code execution vulnerability with maximum severity, but Microsoft states no customer action is required and there is no evidence of PoC, exploitation, or available patch.

    10000125
    85 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-33819 — CVSS 10/10 ██████████ Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/H635k5K2Di

    Post summary

    CVE-2026-33819 is a critical deserialization flaw in Microsoft Bing that enables remote code execution; a patch has already been issued.

    1000070
    28 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-33819-microsoft-bing #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet merely links to a research article about CVE-2026-33819, providing no further details or indicators of exploitation, patching, or technical depth.

    0000020
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33819 Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-33819

    Post summary

    The post announces a deserialization flaw in Microsoft Bing that permits remote code execution, but it offers no PoC, exploit tools, evidence of active misuse, or patch information.

    00000126
    57.3K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability https://www.aakashrahsi.online/post/cve-2026-33819 https://t.co/JhOEMwotcl

    Post summary

    The tweet links to a post announcing the new CVE-2026-33819, a remote code execution vulnerability in Microsoft Bing.

    0000032
    1 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-33819 is under active exploitation—attackers can execute remote code via Microsoft Bing's deserialization vulnerability. This poses a critical threat to network security. Patch now. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #Microsoft https://t.co/HulfY7Ssxj

    Post summary

    CVE-2026-33819 is actively exploited for remote code execution through a Microsoft Bing deserialization flaw, and a patch is urgently recommended.

    0000041
    55 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Microsoft Bing (CVE-2026-33819) https://vuldb.com/vuln/359230

    Post summary

    An important vulnerability (CVE‑2026‑33819) affecting Microsoft Bing has been added to a vulnerability database, indicating a recent disclosure.

    0000074
    2.1K followersView on X
  • WindowsForum@windowsforum
    General

    🪟 CVE-2026-33819 “Bing RCE” is MSRC’s way of saying: stop scrolling, start triaging. Confidence signals matter because attackers love uncertainty—and Defender needs no extra mystery. https://windowsforum.com/threads/cve-2026-33819-bing-rce-how-msrc-confidence-signals-shape-defender-triage.414944/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #RemoteCodeExecution #BingSecurity https://t.co/vCVXDPDUd5

    Post summary

    The post points to a forum thread on MSRC confidence signals for CVE-2026-33819 (Bing RCE) but provides no concrete PoC, exploit code, patch, or detailed technical information.

    0000075
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftbing---

Explore more