Ray’s spoofable User-Agent guard becomes a browser-based RCE now on CISA’s KEV list
Ray’s anti-browser defense was a User-Agent header check that Firefox and Safari let you forge through the fetch API. Combined with DNS rebinding, it becomes a remote code execution triggered by a single page visit — added to CISA’s KEV catalog on August 17, 2026 with a fix deadline of August 20.