Junglewise Threat Intelligence

CVE-2026-32186: Microsoft Bing SSRF and elevation of privilege

CVE-2026-32186 · Severity: critical · CVSS 10 · Published 2026-04-03

Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in Microsoft Bing, the web search engine service. An unauthorized attacker could exploit this flaw to gain elevated privileges within the system. This could lead to unauthorized access to sensitive data or full control over service components, potentially impacting user privacy and service integrity.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Microsoft Bing. The flaw allows an unauthenticated attacker to send specially crafted network requests from the Bing server infrastructure. By exploiting this, an attacker can bypass network security controls to access internal resources or metadata services, leading to a full elevation of privilege. The vulnerability is reachable over the network without user interaction and has been assigned a CVSS score of 10.0 due to its potential for total impact on confidentiality, integrity, and availability. As an exclusively hosted service, Microsoft typically manages the remediation on the backend.

Affected products

  • Microsoft Bing All versions (Exclusively Hosted Service)

Timeline

  • 2026-04-03: disclosed: Initial publication of the vulnerability advisory.
  • 2026-04-03: advisory: Microsoft released the security update guide for CVE-2026-32186.

References

Related threats