Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Bing Images Flaws Patched Amid Security Concerns

Critical Bing Images Flaws Patched Amid Security Concerns

Posted on July 24, 2026 By CWS

Microsoft has addressed significant security vulnerabilities in its Bing Images service, which exposed its servers to potential exploitation. The vulnerabilities, identified as critical by Microsoft, were discovered in the image-processing infrastructure, allowing attackers to execute remote code using specially crafted SVG files.

Discovery and Impact

The vulnerabilities, brought to light by the AI security researcher XBOW, have been patched following their responsible disclosure. These flaws threatened Microsoft’s Bing servers, granting attackers potential SYSTEM-level access. Microsoft tagged these issues as critical, with each scoring a maximum of 9.8 on the CVSS scale.

Specifically, CVE-2026-32194 was linked to command injection in Bing’s image-processing segment, vulnerable through the “Search by Image” feature. Another, CVE-2026-32191, was found in the server-side image ingestion path related to Bing’s reverse image search. A separate issue, CVE-2026-21536, involved unrestricted file uploads in the Microsoft Devices Pricing Program.

Technical Analysis

The vulnerabilities were initially unearthed when Bing’s reverse image search was manipulated to fetch attacker-controlled URLs, a classic server-side request forgery (SSRF) scenario. The SSRF led researchers to identify inconsistent server responses, suggesting deeper server processing rather than simple image retrieval.

Further investigation revealed that the image-processing component used an ImageMagick-style engine, which was vulnerable to command injection via SVG files. SVG files, being XML-based, can include commands that, when improperly handled, execute as system commands.

The exploit was possible through two paths: direct image uploads via Bing’s endpoint or through external hosting pulled in by the SSRF vulnerability.

Lessons and Mitigation

Organizations utilizing similar image-processing systems should implement several security measures. Disabling shell-invoking and pipe-based delegate functions in image converters like ImageMagick is recommended. Restrictive configurations should be enforced to prevent high-risk formats unless necessary.

Moreover, egress controls and sandboxing image conversion processes with limited privileges are vital. It’s crucial to build validation systems that consider different server environments to ensure all potential exploitation signals are detected.

Microsoft has resolved these vulnerabilities in its Bing Images service, highlighting the importance of treating image conversion systems as security-critical code. This incident serves as a broader warning for any service handling image uploads or external URL fetches to maintain rigorous security standards.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. Integrate ANY.RUN With Your SOC Now.

Cyber Security News Tags:Bing, bug bounty, cloud service, CVE, Cybersecurity, image processing, ImageMagick, Microsoft, remote code execution, Security, SVG file, system security, Vulnerabilities, XBOW

Post navigation

Previous Post: Certighost Flaw in AD CS Allows Domain Compromise
Next Post: Critical Foxit Vulnerability Allows SYSTEM Privilege Escalation

Related Posts

Critical SonicWall SSL VPN Vulnerability Let Attackers Trigger DoS Attack Critical SonicWall SSL VPN Vulnerability Let Attackers Trigger DoS Attack Cyber Security News
Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Cyber Security News
Malicious Extensions Target AI Chat Platforms Users Malicious Extensions Target AI Chat Platforms Users Cyber Security News
Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data Cyber Security News
New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector Cyber Security News
How ClickFix and Multi-Stage Frameworks Are Breaking Enterprise Defenses How ClickFix and Multi-Stage Frameworks Are Breaking Enterprise Defenses Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark