Researchers disclosed critical remote code execution vulnerabilities in Microsoft's Bing Images service (CVE-2026-32194, CVE-2026-32195) that allow crafted SVGs to execute commands as SYSTEM, plus Certighost in Active Directory Certificate Services. Multiple patches have been issued following researcher disclosures.
7 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Security researchers disclosed details of two Microsoft vulnerability cases this week: Certighost, an Active Directory Certificate Services flaw tracked as CVE-2026-54121, and two Bing Images flaws tracked as CVE-2026-32194 and CVE-2026-32191 [thehackernews.com#1][cybersecuritynews.com#1][thehackernews.com#2][cybersecuritynews.com#2]. Microsoft patched the AD CS issue in its July 14 security updat
🤖 CVE-2026-32194 & CVE-2026-32195 (critical): Crafted SVGs submitted to Bing Images run commands as SYSTEM on Microsoft's image-processing workers. Two CVEs issued after patches. Technical writeup from XBOW. 🔗 https:// thehackernews.com/2026/07/bing -images-flaws-let-crafted-svgs-run.html # CVE # RCE # Microsoft # InfoSec
⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im… https
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers https:// thehackernews.com/2026/07/bing -images-flaws-let-crafted-svgs-run.html
# OT # Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, Open