• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / CISA orders 3-day fix for actively exploited Ray flaw

CISA orders 3-day fix for actively exploited Ray flaw

byLotfi Ben Taleb
August 19, 2026
in Security
Reading Time: 2 mins read
CISA orders 3-day fix for actively exploited Ray flaw
Share on Facebook
Share on Twitter

CISA added a critical Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog on Monday, citing evidence of active exploitation.

Ray is the open-source, Python-native framework used to scale AI and machine-learning workloads from a laptop to a cluster; it is built into pipelines at Amazon, Apple and OpenAI, according to The Register. The bug carries a CVSS v4 score of 9.4 and was first disclosed in November 2025, per the NVD advisory.

How the browser becomes the attacker

Vulnerable Ray builds try to keep browsers away from the local Ray API by rejecting any request whose User-Agent header starts with “Mozilla”. Firefox and Safari both let a page’s own JavaScript rewrite that header via the Fetch API, so the check does nothing. Combined with DNS rebinding, a malicious site or a bad ad can reach a developer’s local Ray instance directly.

“This vulnerability impacts developers running development/testing environments with Ray,” the project’s maintainers said, as quoted by The Register. “If they fall victim to a phishing attack, or are served a malicious ad, they can be exploited, and arbitrary shell code can be executed on their developer machine. This attack can also be leveraged to attack network-adjacent instances of Ray by leveraging the browser as a confused deputy intermediary to attack Ray instances running inside a private corporate network.”

Ray 2.52.0 fixes the flaw.

Three days, no explanation

CISA is giving federal civilian agencies just three days to remediate, not the usual 14, under the compressed window that Binding Operational Directive 26-04 permits for vulnerabilities it treats as especially risky. The agency did not say why this one qualifies, and left the KEV catalogue’s “known to be used in ransomware campaigns” field marked unknown. That combination, a maximally tight deadline paired with a shrug on ransomware activity, is the detail worth sitting with: it reads as CISA acting on exploitation evidence it is not disclosing, rather than on a documented ransomware playbook.

What to watch

Anyone running Ray in a dev or test environment, not just federal agencies, should treat 2.52.0 as mandatory rather than optional, since the browser-based attack path means exposure is not limited to internet-facing instances. Worth watching whether CISA or Ray’s maintainers say more about what the observed exploitation has actually looked like.

Image: Tumisu / Pixabay

Tags: cisaopen-sourcerayvulnerability
Previous Post

Framework Laptop 12 switches to Wildcat Lake, ships October

Next Post

ASUS adds auto-shutdown to GPU Tweak III for 12V-2×6 cards

Related Posts

A dark gaming room with an open-panel desktop PC lit by orange RGB fans beside a monitor, mechanical keyboard and mouse
Gaming

Modern Warfare 4 PC beta dates and shader fix

August 21, 2026
A black Dell laptop open on a white desk in an office, its lid logo visible and a Windows lock screen on the display
Hardware

Dell 15 laptop starts at $699.99 with Intel Core Series 3

August 21, 2026
Close-up of a GeForce GTX graphics card's cooling fan and backplate logo
Software

GeForce Now Firefox support goes live

August 21, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

A GeForce RTX graphics card installed in a PC with its power cable connected

ASUS adds auto-shutdown to GPU Tweak III for 12V-2×6 cards

August 19, 2026
Close-up of server racks in a data center highlighting modern technology infrastructure.

OpenAI details new safeguards after Hugging Face hack

August 21, 2026
T-Force Delta RGB DDR5 memory modules on vibrant yellow surface.

DDR5 prices up 416% in a year, 10 times their record low

August 19, 2026
A dark blue mesh-covered cylindrical smart speaker on a wooden surface

HomePad code hints at an Apple Watch-style interface

August 20, 2026
Next Post
A GeForce RTX graphics card installed in a PC with its power cable connected

ASUS adds auto-shutdown to GPU Tweak III for 12V-2x6 cards

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply