CVE-2026-32186
Published: 03 April 2026
Summary
CVE-2026-32186 is a critical-severity SSRF (CWE-918) vulnerability in Microsoft Bing. Its CVSS base score is 10.0 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 19.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Threat & Defense at a Glance
Threat & Defense Details
Mitigating Controls (NIST 800-53 r5)AI
Directly mitigates the SSRF vulnerability by requiring identification, reporting, correction, and verification of the specific flaw in Microsoft Bing.
Enforces validation of inputs such as URLs to prevent attackers from forging server-side requests leading to privilege escalation.
Monitors and controls network communications at boundaries to block or detect unauthorized outbound requests exploited in this SSRF.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
SSRF in public-facing Bing service is remotely exploitable without auth (T1190); description explicitly states resulting privilege elevation and infrastructure compromise (T1068).
NVD Description
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
Deeper analysisAI
CVE-2026-32186 is a server-side request forgery (SSRF) vulnerability, mapped to CWE-918, affecting Microsoft Bing. Published on 2026-04-03T18:16:24.993, it carries a CVSS v3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), marking it as critically severe due to its potential for high-impact confidentiality, integrity, and availability effects across a scoped attack surface.
The vulnerability enables an unauthorized attacker to exploit it remotely over a network with low attack complexity, requiring no privileges, user interaction, or special conditions. Successful exploitation allows the attacker to elevate privileges, potentially compromising the targeted Bing infrastructure.
Microsoft's Security Response Center has published an update guide detailing mitigation and patching information at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32186. Security practitioners should consult this advisory for specific remediation steps.
Details
- CWE(s)