CyberICT

CVE-2026-32191

Microsoft · Published March 19, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Bing Images Remote Code Execution Vulnerability. Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Affected Products

  • Microsoft Bing Images

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C