CVE-2026-32194: exploitation status and patch state
CVE-2026-32194 · CVSS 9.8 CRITICAL · EPSS 1%
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
Is CVE-2026-32194 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.