Vulnerability Management Critical vulnerability in Ray framework allows remote code execution August 19, 2026 Share By SC Staff A critical vulnerability in the open-source Ray framework, used for scaling Python and machine-learning workloads, is being actively exploited by attackers, according to the Cybersecurity and Infrastructure Security Agency (CISA). The flaw, tracked as CVE-2025-62593, allows for remote code execution on vulnerable Ray systems, according to a recent report by The Register. The vulnerability, rated 9.4 under CVSS v4, was disclosed in November 2025 and allows attackers to exploit browsers like Firefox and Safari to achieve remote code execution (RCE) on a vulnerable Ray system. This is possible because vulnerable Ray versions attempt to block browser requests by checking if the User-Agent header starts with "Mozilla," a check that Firefox and Safari can bypass. Developers running Ray could trigger the exploit by visiting a malicious website or encountering a compromised ad, enabling attackers to use DNS rebinding to access the local Ray service. The vulnerability impacts developers running development and testing environments, potentially allowing arbitrary shell code execution on their machines. It can also be used to attack network-adjacent Ray instances. Ray 2.52.0 addresses the flaw, and CISA has mandated a three-day remediation window for US federal agencies due to the perceived risk. Source: The Register SC Staff Related Patch/Configuration Management Microsoft removes WMIC tool from Windows 11 SC Staff August 19, 2026 WMIC, a legacy command-line utility for interacting with Windows Management Instrumentation (WMI), has been progressively phased out. Vulnerability Management AI-powered defense strategy: How to find and fix vulnerabilities at machine speed Paul Wagenseil August 18, 2026 As vulnerability discovery is industrialized, remediation must combine AI automation, environmental context and human expertise. Vulnerability Management New Unisoc modem flaw allows Android kernel access SC Staff August 18, 2026 Researchers demonstrated this exploit chain on a Realme C33 smartphone, confirming its effectiveness on devices with specific Android security patches. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds