Back Feeds.4Sysops Critical remote code execution flaws patched in Microsoft Bing image processing
Microsoft recently addressed two critical remote code execution vulnerabilities, CVE-2026-32194 and CVE-2026-32191, discovered within the Bing image- service. These flaws allowed attackers to execute arbitrary commands with SYSTEM privileges on Windows Server 2022 Datacenter nodes or root access on Linux backend workers. The vulnerabilities were identified by the security firm XBOW, which demonstrated that malicious SVG files could trigger command injection during server-side image parsing. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
