Future Monitor 한국어

Signal Bing Images RCEs: How XBOW Found Three Critical Flaws

Summary

XBOW disclosed the exploit mechanism for three Bing Images vulnerabilities on 23 July 2026, after Microsoft requested that publication wait until patching was complete. The three flaws, CVE-2026-32194, CVE-2026-32191 and CVE-2026-21536, all carry a CVSS score of 9.8 and require no authentication, cookies or user interaction. A crafted SVG achieved command execution as NT AUTHORITY\SYSTEM on Microsoft's production image processing workers, and as root on the same team's Linux machines. The proof of concept ran to three lines, using an xlink:href attribute beginning with a pipe character to exploit a conversion layer where ImageMagick delegate functionality remained enabled. This repeats the failure class of ImageTragick, CVE-2016-3714, from 2016. XBOW was credited as the finder of all three in Microsoft's acknowledgement list and entered the top ten of the bug bounty leaderboard, the first and only AI to reach that ranking.

Classification

Secondary topicsAI & Computing
Region menusGlobal
Impactscope:global
Time horizon0-3 years (2026-07-28)
Last updated2026-07-28T14:28:30.174819+00:00

Evidence 1

Part of trends 0

No objects.

Directly linked issues 0

No objects.

Public id: fm-cdea7fca95e9