CVE-2026-33819

CRITICAL

Microsoft Bing Remote Code Execution Vulnerability

Title source: cna

Description

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Scores

CVSS v3 10.0
EPSS 0.0027
EPSS Percentile 50.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
Microsoft/Microsoft Bing -
Published Apr 23, 2026
Tracked Since Apr 24, 2026