AI Security Agent Discovers Two Critical Remote Code Execution Vulnerabilities in Microsoft Bing
An autonomous offensive-security agent named XBOW has identified two critical remote code execution (RCE) vulnerabilities in Microsoft Bing Images. These flaws, CVE-2026-32194 (command injection via 'Search by Image' upload) and CVE-2026-32191 (OS command injection via the crawler route), both carry a CVSS score of 9.8 and are exploitable without authentication.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.