CRITICALVulnerability
Global

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

·Source: The Hacker News

Updated:

Executive Summary

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and

Analysis

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and

Indicators of Compromise (1)

CVE (1)
CVE-2026-32194
Source Attribution

Originally published by The Hacker News on Jul 24, 2026.

Related Threats