Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

CISA gives feds 3 days to fix actively exploited Ray RCE bug

The Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal civilian agencies three days to patch a critical vulnerability in Ray, an open-source framework widely used for scaling Python and machine-learning workloads. The flaw, CVE-2025-62593, allows remote code execution (RCE) through Firefox or Safari browsers, despite the framework attempting to block such requests.

Major tech companies like Amazon, Apple, and OpenAI utilize Ray. The vulnerability stems from Ray's inability to properly handle browser requests due to Firefox and Safari's handling of the User-Agent header. An attacker can exploit this by visiting a malicious website or receiving a malicious ad, potentially leading to arbitrary shell code execution on the user's machine.

CISA's urgency in demanding a swift response, as opposed to the usual 14-day window, remains unexplained. Nevertheless, the agency cited Binding Operational Directive 26-04, which permits such a short notice for particularly risky vulnerabilities. Ray 2.52.0 addresses the issue, but authentication remains disabled by default, as Ray historically assumed a trusted network environment.

The advisory highlighted Ray's lack of authentication on critical endpoints as a contributing factor to the attack's feasibility.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Why Google Won't Index Your Pages: 4 GSC Fixes

Originally published on echoeffect.net . If you have been inside Google Search Console recently and clicked into the Pages report (previously called Index Coverage), you may have seen a section titled…

More from Tuesday 18 August →