{"id":43497,"date":"2026-08-18T21:19:55","date_gmt":"2026-08-18T21:19:55","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=43497"},"modified":"2026-08-18T21:19:55","modified_gmt":"2026-08-18T21:19:55","slug":"cisa-gives-feds-3-days-to-fix-actively-exploited-ray-rce-bug","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=43497","title":{"rendered":"CISA gives feds 3 days to fix actively exploited Ray RCE bug"},"content":{"rendered":"<p>CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning workloads. Tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, the bug was first disclosed in November 2025. It allows an attacker to use Firefox or Safari to achieve remote code execution (RCE) on a vulnerable Ray system. The open source distributed computing framework is used and supported by major tech companies, including Amazon, Apple, and OpenAI. Vulnerable Ray versions try to identify and block browser requests by checking whether the User-Agent header begins with &#8220;Mozilla.&#8221; Firefox and Safari, however, allow scripts using the Fetch API to modify that header. A developer running Ray could trigger the exploit simply by visiting a dodgy website or receiving a malicious ad in an affected browser. The attacker can then use DNS rebinding to reach the local Ray service. &#8220;This vulnerability impacts developers running development\/testing environments with Ray,&#8221; the project&#8217;s developers explained. &#8220;If they fall victim to a phishing attack, or are served a malicious ad, they can be exploited, and arbitrary shell code can be executed on their developer machine. &#8220;This attack can also be leveraged to attack network-adjacent instances of Ray by leveraging the browser as a confused deputy intermediary to attack Ray instances running inside a private corporate network.&#8221; Ray 2.52.0 fixes the flaw. CISA gave US federal civilian executive branch agencies three days to remediate it, rather than the standard 14. CISA did not explain the urgency, and marked the catalog&#8217;s &#8220;known to be used in ransomware campaigns&#8221; field as &#8220;unknown.&#8221; However, Binding Operational Directive 26-04 allows the agency to impose a three-day remediation window on vulnerabilities it considers especially risky. Ray is an open source framework that helps developers scale Python and machine-learning workloads from a local environment to a cluster with minimal code changes. Now managed by the Linux Foundation&#8217;s PyTorch Foundation, the project started at UC Berkeley and was commercialized via Anyscale, the startup founded by Ray&#8217;s developers in 2019. According to Anyscale&#8217;s figures as of October 2025, Ray had more than 237 million total downloads, and 7 million per week \u2013 representing a near-tenfold growth year-on-year. Product analysis site NextSprints estimates that Ray has 1 million monthly active users and is used by 60 percent of Fortune 500 companies. The security advisory blamed Ray&#8217;s longstanding lack of authentication on critical endpoints for making the attack possible. Ray&#8217;s security model historically assumed that clusters would run inside a trusted, isolated network, leaving authentication and access control to the surrounding infrastructure. Ray 2.52.0 introduced optional token-based authentication as an additional defense against unauthorized access, although it remains disabled by default. The project continues to recommend deploying clusters inside a controlled network rather than treating authentication as a substitute for isolation. \u00ae<\/p>\n<p><em>Source: <a href='https:\/\/www.theregister.com\/security\/2026\/08\/18\/cisa-gives-feds-3-days-to-fix-actively-exploited-ray-rce-bug\/5289007' target='_blank'>Read the original article on www.theregister.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning workloads. Tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, the bug was first disclosed in November 2025. It allows an attacker to use Firefox or Safari to achieve remote code execution (RCE) [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,36,3],"tags":[13,29,33],"class_list":["post-43497","post","type-post","status-publish","format-standard","hentry","category-important","category-share-suggestions","category-technology","tag-impact-aapl","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/43497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=43497"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/43497\/revisions"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=43497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=43497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=43497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}