CVE-2026-32191

Critical9.8Published on March 19, 2026

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-78
Vendorsmicrosoft

Affected products

VendorsProductVersions
microsoftbing images-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database