type: cve ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [cve, zero-day, sector-technology] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: false
CVE-2026-32194 โ Bing Images SVG RCE (Windows SYSTEM)
CVE-2026-32194 is a critical vulnerability (CVSS 9.8) in Bing's image-processing tier allowing crafted SVGs to achieve Remote Code Execution (RCE) as SYSTEM on Windows servers. Discovered by XBOW and fixed server-side by Microsoft.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-32194 |
| CVSS | 9.8 (Critical) |
| Type | SVG-triggered Remote Code Execution |
| Platform | Windows (SYSTEM-level RCE) |
| Product | Bing Images backend |
| Discovered by | XBOW |
| Fix | Server-side by Microsoft (no patch needed by users) |
Impact
Crafted SVG images uploaded or served through Bing Images could execute arbitrary commands as SYSTEM on Microsoft's production Windows servers. The companion CVE Cve 2026 32191 Bing Images Svg Linux covers the equivalent Linux (root-level) variant.
Both CVEs underscore the risk of server-side image processing pipelines handling user-supplied SVG content, a common vector in content delivery platforms.
Related Pages
- Cve 2026 32191 Bing Images Svg Linux โ Bing Images SVG RCE on Linux (root-level, CVSS 9.8)
- Bing Images Flaws Let Crafted Svgs Run Commands As System On Microsoft S Servers โ Incident page covering both CVEs