Home / Aug 19, 2026 / Story
0
#9 The Hacker News general August 18, 2026 at 06:34 UTC

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

By [email protected] (The Hacker News)

AI Summary

CISA added a critical flaw in Ray, an open-source Python-based distributed computing framework with over 35,000 GitHub stars, to its Known Exploited Vulnerabilities catalog after confirming active exploitation enabling browser-based remote code execution. Ray is widely used to scale AI and ML workloads, making this vulnerability particularly relevant to organizations running AI infrastructure. All Ray deployments should be patched or isolated from public network access immediately.

Relevance score: 79.0/100

# More from August 19