The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers at XBOW found critical command injection flaws in Microsoft's Bing image service that let a crafted SVG file run commands as SYSTEM on Windows workers and root on Linux workers.
- The bugs, tracked as CVE-2026-32194 and CVE-2026-32191 and rated 9.8 in severity, were reported privately and Microsoft patched them server-side before advisories were published on March 19, so users need take no action.
- XBOW published technical details on July 23 after Microsoft asked it to wait until fixes were in place, and neither flaw was recorded as exploited.
- The report stresses that any system running ImageMagick or similar tools on untrusted images should disable delegates, restrict accepted formats, and cut worker network access to avoid the same class of bug.
What to watch next
- Microsoft may update the CVE records' status now that exploit details are public, as records still listed no public disclosure as of July 24.
- Whether other services using ImageMagick-style pipelines disclose similar delegate-based bugs following the disclosure.
Coverage1
1 report
English national1
All filed from India
Named United States · Bing · ImageMagick · Microsoft · Nico Waisman · XBOW
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
