Infosec News Nuggets — August 20, 2026
Brief
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CISA added a critical flaw in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug, rated 9.
4 in severity, stems from Ray’s lack of authentication on core endpoints and can be chained with a DNS rebinding attack so that simply visiting a malicious website or ad in Firefox or Safari triggers remote code execution on a developer’s machine, with the attack also capable of reaching network-adjacent Ray instances inside corporate networks.
Federal agencies have been told to apply the fix, shipped in Ray version 2.
- 0, by August 20.
