Critical RCE Vulnerabilities in Microsoft Bing Image Processing Patched

Critical RCE Vulnerabilities in Microsoft Bing Image Processing Patched

First seen 24 Jul 2026, 18:50 UTC ThehackernewsCybersecuritynewsFeeds.4SysopsTechlomedia.In 83% similarity 70.5

Article Content

Browse articles
ThreatCluster

Microsoft has patched two critical remote code execution vulnerabilities, CVE-2026-32194 and CVE-2026-32191, in its Bing image processing service. Discovered by XBOW, these flaws allowed attackers to execute arbitrary commands with SYSTEM privileges on Windows Server 2022 Datacenter and root access on Linux systems. The vulnerabilities were triggered by maliciously crafted SVG files during server-side image parsing. Microsoft released patches to mitigate these vulnerabilities on July 24, 2026. Organizations using affected systems are urged to apply the updates immediately to prevent potential exploitation.

Key Points: • Two critical RCE vulnerabilities in Bing image processing were patched. • Attackers could execute commands with SYSTEM privileges on Windows and root access on Linux. • Patches were released on July 24, 2026, following discovery by security firm XBOW.

ThreatCluster AI

Timeline

2026-03-19
CVE-2026-32194 published
CVE-2026-32194 was published, detailing a critical RCE vulnerability in Bing image processing.
Feeds.4Sysops
2026-03-19
CVE-2026-32191 published
CVE-2026-32191 was published, highlighting another critical RCE vulnerability in the same service.
Feeds.4Sysops
2026-07-24
Patches released for vulnerabilities
Microsoft released patches for CVE-2026-32194 and CVE-2026-32191 to address the critical vulnerabilities.
Thehackernews

Community

Browse all →