AI Security Agent Discovers Two Critical Remote Code Execution Vulnerabilities in Microsoft Bing

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-26T19:49:00Z
Category: technology
Source: The Wall Street Journal

An autonomous offensive-security agent named XBOW has identified two critical remote code execution (RCE) vulnerabilities in Microsoft Bing Images. These flaws, CVE-2026-32194 (command injection via 'Search by Image' upload) and CVE-2026-32191 (OS command injection via the crawler route), both carry a CVSS score of 9.8 and are exploitable without authentication.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai