Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Bing Images Flaws Patched Amid Security Concerns

Critical Bing Images Flaws Patched Amid Security Concerns

Posted on July 24, 2026 By CWS

Microsoft has addressed significant security vulnerabilities in its Bing Images service, which exposed its servers to potential exploitation. The vulnerabilities, identified as critical by Microsoft, were discovered in the image-processing infrastructure, allowing attackers to execute remote code using specially crafted SVG files.

Discovery and Impact

The vulnerabilities, brought to light by the AI security researcher XBOW, have been patched following their responsible disclosure. These flaws threatened Microsoft’s Bing servers, granting attackers potential SYSTEM-level access. Microsoft tagged these issues as critical, with each scoring a maximum of 9.8 on the CVSS scale.

Specifically, CVE-2026-32194 was linked to command injection in Bing’s image-processing segment, vulnerable through the “Search by Image” feature. Another, CVE-2026-32191, was found in the server-side image ingestion path related to Bing’s reverse image search. A separate issue, CVE-2026-21536, involved unrestricted file uploads in the Microsoft Devices Pricing Program.

Technical Analysis

The vulnerabilities were initially unearthed when Bing’s reverse image search was manipulated to fetch attacker-controlled URLs, a classic server-side request forgery (SSRF) scenario. The SSRF led researchers to identify inconsistent server responses, suggesting deeper server processing rather than simple image retrieval.

Further investigation revealed that the image-processing component used an ImageMagick-style engine, which was vulnerable to command injection via SVG files. SVG files, being XML-based, can include commands that, when improperly handled, execute as system commands.

The exploit was possible through two paths: direct image uploads via Bing’s endpoint or through external hosting pulled in by the SSRF vulnerability.

Lessons and Mitigation

Organizations utilizing similar image-processing systems should implement several security measures. Disabling shell-invoking and pipe-based delegate functions in image converters like ImageMagick is recommended. Restrictive configurations should be enforced to prevent high-risk formats unless necessary.

Moreover, egress controls and sandboxing image conversion processes with limited privileges are vital. It’s crucial to build validation systems that consider different server environments to ensure all potential exploitation signals are detected.

Microsoft has resolved these vulnerabilities in its Bing Images service, highlighting the importance of treating image conversion systems as security-critical code. This incident serves as a broader warning for any service handling image uploads or external URL fetches to maintain rigorous security standards.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. Integrate ANY.RUN With Your SOC Now.

Cyber Security News Tags:Bing, bug bounty, cloud service, CVE, Cybersecurity, image processing, ImageMagick, Microsoft, remote code execution, Security, SVG file, system security, Vulnerabilities, XBOW

Post navigation

Previous Post: Certighost Flaw in AD CS Allows Domain Compromise

Related Posts

Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack Cyber Security News
SoundCloud Data Breach Exposes 29.8 Million Personal users Details SoundCloud Data Breach Exposes 29.8 Million Personal users Details Cyber Security News
Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Cyber Security News
Microsoft Defender Identifies New Trojanized Gaming Tool Threat Microsoft Defender Identifies New Trojanized Gaming Tool Threat Cyber Security News
Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands Cyber Security News
Bitwarden CLI Hit by Supply Chain Attack via GitHub Actions Bitwarden CLI Hit by Supply Chain Attack via GitHub Actions Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark