Feeds.4Sysops
Critical RCE Vulnerabilities in Microsoft Bing Image Processing Patched
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has patched two critical remote code execution vulnerabilities, CVE-2026-32194 and CVE-2026-32191, in its Bing image processing service. Discovered by XBOW, these flaws allowed attackers to execute arbitrary commands with SYSTEM privileges on Windows Server 2022 Datacenter and root access on Linux systems. The vulnerabilities were triggered by maliciously crafted SVG files during server-side image parsing. Microsoft released patches to mitigate these vulnerabilities on July 24, 2026. Organizations using affected systems are urged to apply the updates immediately to prevent potential exploitation.
Key Points: • Two critical RCE vulnerabilities in Bing image processing were patched. • Attackers could execute commands with SYSTEM privileges on Windows and root access on Linux. • Patches were released on July 24, 2026, following discovery by security firm XBOW.