CVE-2026-32194

Published Mar 19, 2026

Last updated 5 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32194 is a command injection vulnerability found in Microsoft Bing Images. This flaw stems from the improper neutralization of special elements within a command, which allows an unauthorized attacker to execute code. The vulnerability is specifically reachable through the public "Search by Image" upload feature. Discovered by the security firm XBOW, this vulnerability enabled attackers to execute code on Microsoft's production servers. It is related to the image processing pipeline within Bing Images.

Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service
Products
bing_images

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-77

Social media

Hype score
Not currently trending
  1. XBOW, an autonomous AI pentesting agent, found two critical flaws in Bing image-processing servers: a crafted SVG ran commands as SYSTEM and as root. CVE-2026-32194 and CVE-2026-32191, both CVSS 9.8. Microsoft patched server-side before disclosure on July 23. #AIsecurity #CVE

    @SEatTrend

    27 Jul 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 1/3 A single crafted SVG uploaded to Bing image search ran commands as SYSTEM on Microsoft's own servers. Two OS command injection bugs (CVE-2026-32194, CVE-2026-32191) let an image reach a shell with full privileges. Microsoft has patched. #CyberSecurity #InfoSec #CVE https://t.

    @CyberTLDR

    25 Jul 2026

    398 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  3. ⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE

    @BetoDay

    25 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Two critical RCE flaws (CVSS 9.8), CVE-2026-32194 & CVE-2026-32191, in Bing Images let attackers hijack backend servers using just a crafted SVG file — achieving SYSTEM-level access via command injection in the image-processing pipeline. Discovered by AI security rese

    @techepages

    24 Jul 2026

    1130 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. Critical vulnerabilities in Bing Images, identified as CVE-2026-32194 and CVE-2026-32191, allow remote code execution via crafted SVG files. These flaws, now patched, underscore the importance of robust input validation in image-processing pipelines to prevent command injection h

    @dailytechonx

    24 Jul 2026

    192 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.