CVE-2026-32191
Microsoft · Published March 19, 2026
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Bing Images Remote Code Execution Vulnerability. Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
Affected Products
- Microsoft Bing Images
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C