< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-24T17:15:17+05:30

Bing Images Vulnerability Allows Command Execution via Crafted SVGs on Microsoft Servers

Microsoft's Bing Images service was found to have critical vulnerabilities allowing crafted SVGs to execute commands with SYSTEM privileges on its servers. Two CVEs, CVE-2026-32194 and CVE-2026-32191, were disclosed after XBOW's responsible disclosure and Microsoft's server-side remediation.

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet.

XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and

Read original article

*** END OF TRANSMISSION ***