Bottom line: CISA has added a critical, actively exploited Ray vulnerability with browser-based RCE potential to its KEV catalog, which should prompt organizations with Ray-based AI/ML infrastructure to immediately review and secure their systems.
The US agency CISA has added a critical vulnerability in the open-source framework Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The affected software is used by numerous enterprises to scale AI and ML workloads.
Ray is an open-source, Python-native framework for distributed computing, specifically designed to scale artificial intelligence and machine learning workloads. According to the original source’s report, the underlying GitHub project counts a significant number of users in production environments, underscoring the scope of the potential attack surface. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on Monday, explicitly citing evidence of active exploitation already occurring in the wild.
According to the description, the flaw enables Remote Code Execution (RCE) that can be triggered via the browser. For organizations running Ray in their ML pipelines, training clusters, or inference infrastructure, this poses an immediate risk of compromise to compute nodes, which frequently hold sensitive training data, model artifacts, and access keys to further cloud resources. Since Ray clusters are typically internally networked and often access cloud infrastructure with elevated privileges, successful exploitation can serve as a springboard for lateral movement within the infrastructure.
For CISOs with ties to US federal agencies, the KEV listing creates a binding remediation deadline under Binding Operational Directive 22-01; organizations outside this scope should nonetheless treat the listing as a strong signal to inventory their own Ray usage, identify affected instances, and promptly review available patches or mitigation measures. As the original report does not name a specific CVE ID, affected version numbers, or a patch timeline, security officers should consult Ray’s vendor page and the official CISA KEV entry to verify the exact technical details and recommended countermeasures before implementing remediation steps.
Source: thehackernews.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.