Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-32194

Bing Image Processing Executes User-Supplied SVG as SYSTEM

A crafted SVG submitted to Bing Images ran commands as SYSTEM on Microsoft's production image servers. CVE-2026-32194 (CVSS 9.8) is now patched.

cat cve-2026-32194.json
Vendor
Microsoft
Product
Bing Image Processing Infrastructure
CVSS
9.8
EPSS (exploit probability)
N/A
Status
patched
Published

Microsoft’s Bing image search processed user-supplied SVG files inside a worker process running as NT AUTHORITY\SYSTEM on Windows and as root on Linux. Security firm XBOW reported that a crafted SVG could execute arbitrary commands in that context across multiple hosts in Bing’s image-processing fleet — the issue was in the tier’s design, not isolated to a single machine.

Microsoft assigned multiple critical CVEs addressing the findings. CVE-2026-32194, rated CVSS 9.8 Critical, covers the primary server-side code execution path on the Windows side. Patches are deployed to Microsoft’s infrastructure. No end-user action is required. Full research detail is available in the XBOW writeup via The Hacker News.