Threat Intelligence

US Cybersecurity Agency Warns of Actively Exploited Flaw in AI Framework 'Ray'

The Hacker News · 18 Aug 2026
Key Takeaway If your business uses AI or data-science tools built on open-source frameworks like Ray, check with your developers or vendors now to confirm patches have been applied.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw affecting Ray, a popular open-source framework used to scale artificial intelligence and machine learning workloads, to its Known Exploited Vulnerabilities (KEV) catalog. This designation confirms that attackers are actively exploiting the flaw in real-world attacks, not just theorising about it.

Ray is widely used by developers and data science teams to distribute computing tasks across multiple machines, making it a valuable tool for organisations building AI-powered products. The flaw can potentially be triggered through a browser, leading to remote code execution — meaning an attacker could run malicious commands on an affected system without needing direct access to it.

While Ray is more commonly used by larger tech teams and AI developers than typical small businesses, any Australian SMB that relies on custom AI or data science tools — whether built in-house or through a vendor — should check whether Ray is part of their technology stack. CISA's KEV listing is a strong signal that patching should be treated as urgent, not optional.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.