importantSYS.SOURCE: The Hacker News• 2026-08-18T12:04:20+05:30
CISA Identifies Critical Ray Vulnerability Enabling Browser-Based Remote Code Execution
CISA has added a critical vulnerability (CVE-2025-62593) in the Ray framework to its KEV catalog, enabling browser-based remote code execution through DNS rebinding attacks. The flaw affects development environments and has been actively exploited, with mitigations required by August 20, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than
*** END OF TRANSMISSION ***