← Back to News
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE --> #1 Trusted Cybersecurity News Platform

Followed by 5.70+ million      Get the Latest News Home Newsletter

Webinars Home Threat Intelligence Vulnerabilities Cyber Attacks Webinars Expert Insights Awards  

 Resources Webinars Awards Free eBooks About Site About THN Jobs Advertise with us Contact/Tip Us  Reach

out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a question or leave a

comment/feedback! Follow Us On Social Media       RSS Feeds 

Email Alerts CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE Ravie

LakshmananAug 18, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency

(CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing

evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale

artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than 43,500 stars and

has been forked over 7,900 times. The vulnerability in question relates to CVE-2025-62593 (CVSS score: 9.4), which can

result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding

attack. "Due to the longstanding decision by the Ray Development team to not implement any sort of authentication on

critical endpoints, like the /api/jobs & /api/job_agent/jobs/ has once again led to a severe vulnerability that

allows attackers to execute arbitrary code against Ray," according to an advisory shared by Ray maintainers in November

2025. "This time in a development context via the browsers Firefox and Safari." The issue, at its core, stems from

insufficient controls against browser-based attacks, specifically scenarios where the User-Agent header can be modified.

"Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer

running Ray who inadvertently visits a malicious website, or is served a malicious advertisement," the project

maintainers added. It's worth noting that the defect primarily impacts developers running development/testing

environments with Ray. Should a targeted victim fall prey to a phishing attack, or be served a malicious ad, it can lead

to the execution of arbitrary shell code on their machine. The project maintainers also noted that the attack can also

be extended to attack network-adjacent instances of Ray by leveraging the browser as a confused deputy intermediary to

target Ray instances running inside a private corporate network. The issue has been addressed in version 2.52.0 of the

Python package. Ray has credited Oligo security researcher Avi Lumelsky with discovering the fetch bypass and Jonathan

Leitschuh for coming up with the DNS rebinding attack. CISA has not shared any details of how the vulnerability is being

exploited in the wild. However, a BitSight report from March 2026 revealed that the threat actors behind the RondoDox

DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November

26, 2025, because of the availability of a proof-of-concept (PoC) exploit. According to Oligo, unpatched Ray instances

have also been at the receiving end of cyber attacks that aim to turn infected clusters with NVIDIA GPUs into a

self-replicating cryptocurrency mining botnet as part of a campaign dubbed ShadowRay 2.0. In light of active

exploitation of CVE-2025-62593, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary

fixes and mitigations by August 20, 2026. Found this article interesting? Follow us on Google News, Twitter and LinkedIn

to read more exclusive content we post. SHARE     Tweet Share

Share Share  Share on Facebook Share on Twitter Share on Linkedin

Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook

Messenger Share on Telegram SHARE  AI Security, botnet, cryptocurrency, Cyber Attack, ddos, network

security, Open Source, remote code execution, Threat Intelligence, Vulnerability ⚡ Top Stories This Week Azure

Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet

for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking

Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over

N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack

Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm

Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real

Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server

Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With

Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy

Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt

Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1

Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead

to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to

Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the SOC

and Where It Falls Short at Scale Defend Against One-Click AI Memory Poisoning — Download the Cheat Sheet

Benchmark Your Defenses Against 338M+ Attack Simulations — Download the Blue Report 2026 Cybersecurity Webinars AI

Attacks Are Moving Faster. Watch: How to Prepare Your Security Program for AI-Powered Attacks AI can find and chain

vulnerabilities in minutes. This session gives you a practical roadmap to strengthen visibility, response, and

remediation. Register See What 300 Leaders Found Shipping 10–50× More Code? Learn How to Keep Security in

Control AI is helping teams ship code 10–50× faster. This session shows how to keep security from falling

behind. Register ⚡ Latest News Cybersecurity Resources 11 Real Stories: How Identity Exposure Unlocks Active

Attack PathsMap cross-domain privilege escalation to sever breach routes at key choke points. AI and Post-Quantum Are

Now the Board's Problem, and YoursBuild the governance to lead AI adoption and prep for post-quantum. Live at SANS

Raleigh, Nov 2. AI Adoption Is Outpacing Governance, New SANS Survey FindsSee where 536 security pros say AI programs

are falling short. ​ Expert Insights Articles Videos Identity Governance Wasn't Built for Breaches That Happen in

Hours August 17, 2026 Read ➝ The Long Road From Pentest Finding to Verified Fix August 17, 2026

Read ➝ Why Your AI Developer Tools Might Be Your Biggest Security Risk August 17, 2026 Read ➝ The

Blind Spot in Modern Email Security August 10, 2026 Read ➝ Get the Latest News in Your Inbox Get the

latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free. Email Connect

with us! 2,000,000 Followers 725,000 Followers 25,500 Subscribers 172,000 Followers

1,990,000 Followers 60,000 Followers Company About THN Advertise with us Contact Pages Webinars Awards Privacy

Policy  RSS Feeds  Contact Us © 2026 The Hacker News. All Rights Reserved.

Source: thehackernews.com