CVE-2026-28707: Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user com...
Added to the CISA Known Exploited Vulnerabilities catalog on 11 Aug 2026. Vendor: AI/ML. Product: LLM.
Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially o...
Required action: Review and patch if applicable to your AI infrastructure.