August 18, 2026
- CISA confirmed active exploitation of Ray CVE-2025-62593. The critical code-injection flaw can enable browser-based RCE through DNS rebinding and exposure of unauthenticated Ray job-submission interfaces. It is now in CISA’s Known Exploited Vulnerabilities catalog; The Hacker News has additional attack-surface context. · Vulnerabilities & Exploits
in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert