[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsoft-s-servers-mrzytq0s":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":14,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"31a8fcd3-7643-49ac-b293-01ccd87031cd","Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers","bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsoft-s-servers-mrzytq0s","Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM\u002Froot via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded images to Bing before the patch was deployed could have been targeted.","critical","advisory",[12,13],"CVE-2026-32194","CVE-2026-32191",[15,16],"Microsoft","Bing Images","Hunt for SVG file uploads to any internal image processing services or Bing integrations between January and March 2026. Check logs for ImageMagick delegate calls with suspicious parameters. Scan all internet-facing image processing systems for unpatched ImageMagick instances.",[19],"13016a28-8c7c-4327-a8ea-1892a0a172ce",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbing-images-flaws-let-crafted-svgs-run.html","active","2026-07-27T06:05:40.431+00:00","2026-07-25T06:05:43.096673+00:00","2026-07-25T06:08:33.743109+00:00",[28],{"id":19,"title":6,"url":22}]