CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-32194: Bing Images Command Injection via SVG Upload

July 24, 2026

A critical command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM on Microsoft's servers by uploading a crafted SVG file via the 'Search by Image' feature. CVSS 9.8.