type: cve ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [cve, zero-day, sector-technology] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: false
CVE-2026-32191 โ Bing Images SVG RCE (Linux)
CVE-2026-32191 is a critical vulnerability (CVSS 9.8) in Bing's image-processing tier allowing crafted SVGs to achieve Remote Code Execution (RCE) as root on Linux servers. Discovered by XBOW and fixed server-side by Microsoft.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-32191 |
| CVSS | 9.8 (Critical) |
| Type | SVG-triggered Remote Code Execution |
| Platform | Linux (root-level RCE) |
| Product | Bing Images backend |
| Discovered by | XBOW |
| Fix | Server-side by Microsoft (no patch needed by users) |
Impact
Crafted SVG images uploaded or served through Bing Images could execute arbitrary commands as root on Microsoft's production Linux servers. The companion CVE Cve 2026 32194 Bing Images Svg Windows covers the equivalent Windows (SYSTEM-level) variant.
Related Pages
- Cve 2026 32194 Bing Images Svg Windows โ Bing Images SVG RCE on Windows (SYSTEM-level, CVSS 9.8)
- Bing Images Flaws Let Crafted Svgs Run Commands As System On Microsoft S Servers โ Incident page covering both CVEs