CISA adds a critical Ray framework flaw to its KEV catalog after reports of browser-based remote code execution risks impacting enterprise AI systems.