Microsoft Security Flaws: Bing Images RCE and AD Services

Researchers disclosed critical remote code execution vulnerabilities in Microsoft's Bing Images service (CVE-2026-32194, CVE-2026-32195) that allow crafted SVGs to execute commands as SYSTEM, plus Certighost in Active Directory Certificate Services. Multiple patches have been issued following researcher disclosures.

7 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Researchers disclose Microsoft AD CS, Bing Images flaws

kite:cybersecurityother67d ago kagi ↗

Security researchers disclosed details of two Microsoft vulnerability cases this week: Certighost, an Active Directory Certificate Services flaw tracked as CVE-2026-54121, and two Bing Images flaws tracked as CVE-2026-32194 and CVE-2026-32191 [thehackernews.com#1][cybersecuritynews.com#1][thehackernews.com#2][cybersecuritynews.com#2]. Microsoft patched the AD CS issue in its July 14 security updat

🤖 CVE-2026-32194 & CVE-2026-32195 (critical): Crafted SVGs submitted to Bing Images run commands as SYSTEM on Microsoft's image-processing workers. Two CVEs issued after patches. Technical writeup fr

mastodon:infosec-exchangeother67d ago kagi ↗

🤖 CVE-2026-32194 & CVE-2026-32195 (critical): Crafted SVGs submitted to Bing Images run commands as SYSTEM on Microsoft's image-processing workers. Two CVEs issued after patches. Technical writeup from XBOW. 🔗 https:// thehackernews.com/2026/07/bing -images-flaws-let-crafted-svgs-run.html # CVE # RCE # Microsoft # InfoSec

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unau

mastodon:infosec-exchangeother66d ago kagi ↗

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im… https

# OT # Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware relea

mastodon:infosec-exchangeother63d ago kagi ↗

# OT # Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, Open