CVE-2026-32191

Published Mar 19, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32191 is an OS command injection vulnerability found in Microsoft Bing Images. This flaw allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability stems from the improper neutralization of special elements used in OS commands, specifically CWE-78, which enables attackers to inject malicious commands into system shells. This occurs when user-controlled input is passed unsanitized to system command execution functions within Microsoft Bing Images. The vulnerability was discovered by XBOW's autonomous offensive security system, which identified that a crafted SVG submitted to Bing's image search could run commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. Microsoft has since released a security update and fully mitigated this vulnerability for cloud service users, with no customer action required.

Description
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service
Products
bing_images

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-78

Social media

Hype score
Not currently trending
  1. XBOW, an autonomous AI pentesting agent, found two critical flaws in Bing image-processing servers: a crafted SVG ran commands as SYSTEM and as root. CVE-2026-32194 and CVE-2026-32191, both CVSS 9.8. Microsoft patched server-side before disclosure on July 23. #AIsecurity #CVE

    @SEatTrend

    27 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 1/3 A single crafted SVG uploaded to Bing image search ran commands as SYSTEM on Microsoft's own servers. Two OS command injection bugs (CVE-2026-32194, CVE-2026-32191) let an image reach a shell with full privileges. Microsoft has patched. #CyberSecurity #InfoSec #CVE https://t.

    @CyberTLDR

    25 Jul 2026

    398 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  3. ⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE

    @BetoDay

    25 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Two critical RCE flaws (CVSS 9.8), CVE-2026-32194 & CVE-2026-32191, in Bing Images let attackers hijack backend servers using just a crafted SVG file — achieving SYSTEM-level access via command injection in the image-processing pipeline. Discovered by AI security rese

    @techepages

    24 Jul 2026

    1130 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. Critical vulnerabilities in Bing Images, identified as CVE-2026-32194 and CVE-2026-32191, allow remote code execution via crafted SVG files. These flaws, now patched, underscore the importance of robust input validation in image-processing pipelines to prevent command injection h

    @dailytechonx

    24 Jul 2026

    192 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.