Three Unrelated Vendors, One Identical Timeline
Ray is an open-source, Python-native framework used to run AI and ML training and inference workloads, with more than 43,500 GitHub stars and wide use inside enterprise AI infrastructure. A flaw tracked as CVE-2025-62593, with a CVSS score of 9.4, let an attacker combine DNS rebinding with an ordinary browser visit to make a developer's own machine submit code-execution requests to a local Ray cluster, because the authentication check on Ray's API endpoints only verified that the User-Agent header started with the word Mozilla, a value any browser sends by default.
GitLab, the source-control and CI/CD platform used across the industry, disclosed CVE-2026-19478 on 17 August 2026: a GraphQL directive with a CVSS score of 9.4 that let an unauthenticated attacker modify or delete public projects and user data over the network with no user interaction required. Apple patched CVE-2026-65400 on 6 August 2026, a state-management flaw in the credential validation of macOS Screen Sharing, the built-in remote-desktop service that listens on network port 5900. Three unrelated organizations, three unrelated products, one six-day window.
From Patch to Mass Exploitation in Days, Not Months
The RondoDox DDoS botnet incorporated a working exploit for the Ray flaw on 24 November 2025, two full days before the flaw was even publicly disclosed on 26 November 2025, because a proof-of-concept was already circulating. A second campaign, ShadowRay 2.0, specifically scans for unpatched Ray clusters running on NVIDIA GPUs and turns them into self-replicating cryptocurrency-mining botnets, which shows attackers are now deliberately targeting AI training infrastructure for its raw compute power rather than treating it as a generic server.
Apple's Screen Sharing flaw followed the same acceleration. The patch shipped on 6 August 2026, the Netherlands' National Cyber Security Centre confirmed active exploitation against internet-exposed Macs, and in every confirmed case the attacker gained root access and installed a Monero cryptocurrency miner. CISA raised the flaw's severity score from 7.1 to 9.8 on 14 August 2026, eight days after the patch, once it confirmed the exploit had become automatable at scale. CISA added the Ray flaw to its Known Exploited Vulnerabilities catalog on 17 August 2026, with US federal civilian agencies given until 20 August 2026 to patch.
What This Means for Your Patch Cadence
None of this is exotic. Ray sits on AI training clusters, GitLab sits on the software supply chain, and Screen Sharing sits on every Mac an IT team manages remotely, three ordinary pieces of infrastructure that most organizations already run. The gap that used to exist between a vendor releasing a patch and criminals exploiting it at scale has been shrinking for a while, and the Ray timeline shows it can now be negative: the exploit was weaponized before the public even knew the flaw existed.
A monthly or quarterly patch cycle is no longer a defensible security posture for anything with a network-facing admin or developer surface, and self-hosted GitLab, AI training clusters and remotely-managed Mac fleets all fall squarely into that category. The practical response is to track days-from-patch-release-to-full-deployment as a tracked, board-level metric for each of these three categories, with particular attention to self-hosted AI and ML infrastructure, since it is a newer category and most security teams have not yet built a fast patch process for it.
Read next: SAP Commerce Cloud Bug Was Exploited Before Most Patched It | Two SharePoint Bugs Now Chain to Full RCE



