All stories
criticalExploited VulnerabilitiesCVE-2026-32194

Crafted SVG files allow remote command execution as SYSTEM on Microsoft Bing servers

馃毃 Critical vulnerability discovered in Microsoft Bing Images. Attackers can execute arbitrary code over a network by using specially crafted SVG files. Patch immediately to prevent unauthorized remote access.

Summary

A critical command injection vulnerability has been identified in Microsoft Bing Images. The flaw, tracked as CVE-2026-32194, carries a CVSS score of 9.8 due to its high impact on confidentiality, integrity, and availability. An unauthorized attacker can exploit this weakness over a network without requiring user interaction or existing credentials.

Technical details

The vulnerability stems from the improper neutralization of special elements used in a command within the Microsoft Bing Images service. This failure allows for command injection when the system processes certain inputs.

While specific exploitation mechanics are not fully detailed in the official advisory, the flaw resides in how the service handles incoming data that can be manipulated to execute unauthorized commands. This type of vulnerability typically occurs when user-supplied input is passed directly to a system shell or an underlying operating system command without sufficient sanitization.

Why this matters for defenders

Because this vulnerability allows for remote code execution (RCE) over a network, it presents a high risk to any environment interacting with the Bing Images service. An attacker does not need a local account or specialized access to trigger the flaw.

The ability to execute arbitrary commands means an attacker could potentially gain control over the underlying infrastructure, move laterally through a network, or exfiltrate sensitive data processed by the service. Given the high CVSS score of 9.8, this should be treated as a top-priority remediation task for any organization managing these assets.

Defender guidance

Prioritize reviewing all instances and integrations involving Microsoft Bing Images. Because the vulnerability is exploitable over a network, focus on securing the perimeter and ensuring that service-side patches are applied immediately.

Monitor system logs for unusual command execution patterns or unexpected child processes originating from services associated with image processing or web-based media retrieval. If your organization uses automated tools to scrape or process images via Bing, ensure those workflows are monitored for anomalous behavior following the disclosure of this flaw.

Sources

  1. https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
  2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32194
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -