Skip to content
Critical remote code execution flaws patched in Microsoft Bing image processing

Critical remote code execution flaws patched in Microsoft Bing image processing

Feeds.4Sysops IT News July 24, 2026

Microsoft recently addressed two critical remote code execution vulnerabilities, CVE-2026-32194 and CVE-2026-32191, discovered within the Bing image- service. These flaws allowed attackers to execute arbitrary commands with SYSTEM privileges on Windows Server 2022 Datacenter nodes or root access on Linux backend workers. The vulnerabilities were identified by the security firm XBOW, which demonstrated that malicious SVG files could trigger command injection during server-side image parsing. Source

Extracted Entities