Bing image search SVG command injection (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows and root on Linux through CVE-2026-32194 and CVE-2026-32191.
Related Happenings
DRILLAPP JavaScript backdoor through Microsoft Edge
Malware Activity
H score24
First: 16.03.2026 11:07
Last: 16.03.2026 11:07
Sources 1
About this happening:
Observed in February 2026, the DRILLAPP backdoor now runs through Microsoft Edge, giving it file access plus access to the microphone, webcam, and screen...
DRILLAPP JavaScript backdoor through Microsoft Edge
Malware ActivityAbout this happening: Observed in February 2026, the DRILLAPP backdoor now runs through Microsoft Edge, giving it file access plus access to the microphone, webcam, and screen...
Python-based malware deployment with XWorm and Cobalt Strike tooling
Malware Activity
H score28
First: 23.02.2026 17:30
Last: 23.02.2026 17:30
Sources 1
About this happening:
A Python-based malware deployment was uncovered on a compromised Windows system, exposing persistence, obfuscation, and credential-theft activity tied to PayPal abuse...
Python-based malware deployment with XWorm and Cobalt Strike tooling
Malware ActivityAbout this happening: A Python-based malware deployment was uncovered on a compromised Windows system, exposing persistence, obfuscation, and credential-theft activity tied to PayPal abuse...
Visual Studio Code extension malware operation hiding payloads in dependency folders
Malware Activity
H score31
First: 11.12.2025 18:00
Last: 11.12.2025 18:00
Sources 1
About this happening:
The discovery of 19 malicious Visual Studio Code extensions now shows attackers hiding malware inside trusted developer tools, increasing the risk of covert code execution...
Visual Studio Code extension malware operation hiding payloads in dependency folders
Malware ActivityAbout this happening: The discovery of 19 malicious Visual Studio Code extensions now shows attackers hiding malware inside trusted developer tools, increasing the risk of covert code execution...
BigBlack VS Code Marketplace stealer extensions
Malware Activity
H score30
First: 09.12.2025 10:07
Last: 09.12.2025 10:07
Sources 1
About this happening:
The discovery of malicious VS Code Marketplace extensions matters because they can quietly turn a developer workstation into a stealer platform and exfiltrate sensitive da...
BigBlack VS Code Marketplace stealer extensions
Malware ActivityAbout this happening: The discovery of malicious VS Code Marketplace extensions matters because they can quietly turn a developer workstation into a stealer platform and exfiltrate sensitive da...
Timeline
-
24.07.2026 03:00 1 articles · 19h ago
CVE records still show no exploitation for the Bing image-search flaws
Untyped PhaseThe Hacker News checked both CVE records on July 24 and found Microsoft still listing CVE-2026-32194 and CVE-2026-32191 as not exploited. The March advisories had still recorded no public disclosure, so the public status remained unchanged after XBOW's writeup.
Show sources
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers — thehackernews.com — 24.07.2026 14:45
-
23.07.2026 03:00 2 articles · 1d ago
XBOW publishes exploit mechanics for Bing's SVG command injection
Technical Analysis UpdateXBOW released the exploit mechanics for the Bing image-search SVG path after holding them back at Microsoft's request until remediation had landed. The writeup shows a crafted SVG reaching an ImageMagick delegate path and running commands as NT AUTHORITY\SYSTEM on Windows and root on Linux in Microsoft's image-processing workers.
Show sources
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers — thehackernews.com — 24.07.2026 14:45
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers — thehackernews.com — 24.07.2026 14:45
-
19.03.2026 02:00 1 articles · 4mo ago
Microsoft issues Bing image-search command-injection CVEs
Initial DisclosureMicrosoft issued critical CVE-2026-32194 and CVE-2026-32191 for Bing's image-search image-processing tier and rated both 9.8 on the CVSS scale. The records said there was no public disclosure or exploitation when they went up on March 19, and that Microsoft had already fixed both server-side with no customer action required.
Show sources
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers — thehackernews.com — 24.07.2026 14:45