Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [cve, zero-day, sector-technology] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: false

CVE-2026-32191 โ€” Bing Images SVG RCE (Linux)

CVE-2026-32191 is a critical vulnerability (CVSS 9.8) in Bing's image-processing tier allowing crafted SVGs to achieve Remote Code Execution (RCE) as root on Linux servers. Discovered by XBOW and fixed server-side by Microsoft.

Vulnerability Details

Attribute Detail
CVE CVE-2026-32191
CVSS 9.8 (Critical)
Type SVG-triggered Remote Code Execution
Platform Linux (root-level RCE)
Product Bing Images backend
Discovered by XBOW
Fix Server-side by Microsoft (no patch needed by users)

Impact

Crafted SVG images uploaded or served through Bing Images could execute arbitrary commands as root on Microsoft's production Linux servers. The companion CVE Cve 2026 32194 Bing Images Svg Windows covers the equivalent Windows (SYSTEM-level) variant.

Related Pages