Back to advisories

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded images to Bing before the patch was deployed could have been targeted.

CRITICALAdvisoryJul 25, 2026
Action required
Hunt for SVG file uploads to any internal image processing services or Bing integrations between January and March 2026. Check logs for ImageMagick delegate calls with suspicious parameters. Scan all internet-facing image processing systems for unpatched ImageMagick instances.
Affected products
MicrosoftBing Images