thehackernews.com web signal

XBOW's Autonomous Agent Finds Two Critical Microsoft Bing RCEs, Disclosed as CVE-2026-32194 and CVE-2026-32191

Summary

XBOW's autonomous offensive-security agent found two critical Bing Images RCEs — CVE-2026-32194 (command injection via 'Search by Image' upload) and CVE-2026-32191 (OS command injection via the crawler route) — both rated CVSS 9.8 and exploitable with no authentication. A one-pixel SVG whose image reference began with a pipe character escaped ImageMagick's delegate handler to run commands as NT AUTHORITY\SYSTEM on Windows workers and root on Linux workers in Bing's production fleet. Microsoft fixed both server-side before advisories issued in March; XBOW held exploit mechanics until July 23-24 at Microsoft's request.