Security Advisories

Ray Secure Innovations Security Advisories

Official Security Advisory Repository for Ray Secure Innovations Products and Services

Overview

Ray Secure Innovations publishes security advisories to help customers, partners, security researchers, and the broader cybersecurity community understand security vulnerabilities affecting Ray products and services.

This page serves as the official public repository for Ray Secure Innovations security advisories, including vulnerabilities affecting Ray networking devices, security, cloud management, firmware, virtual appliance, API, and other Ray products.

Ray Secure Innovations develops enterprise networking and cybersecurity technologies, including:

  • SD-WAN
  • Firewalls
  • VPN solutions
  • Secure Gateways
  • HSIA
  • Cloud Controller
  • Embedded Linux appliances
  • APIs
  • Networking software
  • Firmware
  • Virtual appliances
  • Future networking and security products
Security NoticeRay Secure Innovations recommends that customers regularly review this page, subscribe to advisory notifications, and keep Ray products updated to supported and fixed versions.

 

Purpose

The purpose of this Security Advisories page is to:

  • Provide a central public source for Ray security advisories.
  • Help customers identify affected products and versions.
  • Provide remediation, mitigation, workaround, and upgrade guidance.
  • Communicate CVE identifiers, CVSS scores, CWE classifications, and severity ratings where applicable.
  • Support coordinated vulnerability disclosure.
  • Support Ray Secure Innovations’ vulnerability management and CVE publication process.
  • Provide a mature public disclosure source suitable for Ray’s current or future role as a CVE Numbering Authority.

 

How Security Advisories Are Published

Ray Secure Innovations publishes a security advisory when a validated vulnerability affects Ray products or services and customer awareness or action is required.

Advisories may be published for vulnerabilities affecting:

  • Ray-developed software or firmware.
  • Ray-managed cloud services.
  • Ray Cloud Management Platform.
  • Ray SD-WAN, firewall, VPN, HSIA and secure gateway products.
  • Ray APIs and web management interfaces.
  • Ray virtual appliances and containerized services.
  • Ray-maintained open-source components.
  • Third-party or open-source components when they affect Ray products and require customer action.

Ray may publish an advisory when:

  1. A vulnerability has been validated.
  2. Affected products and versions have been identified.
  3. Severity and customer impact have been assessed.
  4. A fix, patch, upgrade, mitigation, or workaround is available.
  5. CVE assignment has been completed or requested, where applicable.
  6. Coordinated disclosure requirements have been considered.
  7. Customer guidance is ready for publication.

Ray may also publish an advisory before a complete fix is available when customer protection requires early notification, including cases involving active exploitation, public exploit availability, or significant customer risk.

Advisory Numbering Scheme

Ray Secure Innovations security advisories use the following numbering format:

RAY-YYYY-NNNN

Where:

Field Meaning Example
RAY Ray Secure Innovations advisory prefix RAY
YYYY Year of initial advisory publication 2026
NNNN Sequential advisory number for that year 0001

Example

RAY-2026-0001

This represents the first Ray security advisory published in 2026.

NoteAdvisory IDs are Ray-specific identifiers. They are separate from CVE IDs.

 

Relationship Between Advisory IDs and CVEs

A Ray advisory ID and a CVE ID serve different purposes.

Identifier Purpose Example
Ray Advisory ID Ray’s internal and public advisory tracking identifier RAY-2026-0001
Identifier Purpose Example
CVE ID Globally recognized vulnerability identifier CVE-2026-12345
CWE ID Weakness classification describing the vulnerability type CWE-78
CVSS Vector Standardized vulnerability severity vector CVSS:3.1/… or CVSS:4.0/…

One Ray advisory may reference:

  • One CVE.
  • Multiple CVEs.
  • No CVE, if the issue does not meet CVE eligibility criteria.
  • A third-party CVE, if the vulnerability originates in a dependency or upstream component.

 

CNA Status Wording

Before Ray becomes an approved CNA:
Ray Secure Innovations may request CVE assignment through the appropriate CVE Numbering Authority, Root CNA, or coordination body where applicable.

 

After Ray becomes an approved CNA:
Ray Secure Innovations is a CVE Numbering Authority and may assign CVE IDs for vulnerabilities within its approved CNA scope.

 

Severity Classification

Ray Secure Innovations uses severity ratings to help customers prioritize remediation.

Severity is generally based on CVSS scoring, product-specific risk, deployment exposure, exploitability, impact, and whether exploitation is known or likely.

Severity CVSS Score Range General Meaning
Critical 9.0 – 10.0 Vulnerability may allow severe compromise such as remote code execution,
authentication bypass, complete system compromise, or major cloud tenant
isolation failure
High 7.0 – 8.9 Vulnerability may allow significant compromise, privilege escalation,
sensitive data exposure, security control bypass, or major service impact
Medium 4.0 – 6.9 Vulnerability may require specific conditions, user interaction,
authentication, or limited access but still creates meaningful security risk
Low 0.1 – 3.9 Vulnerability has limited impact, difficult exploitability, or strong
mitigating conditions
Informational N/A Security notice, hardening recommendation, or non-vulnerability security information

 

ImportantCVSS score is an important severity input, but Ray may adjust customer remediation priority based on active exploitation, product exposure, customer impact, and available mitigations.

 

exposure, default configuration, mitigations, and operational impact.

 

CVSS Explanation

Ray Secure Innovations may publish CVSS v3.1 and/or CVSS v4.0 scoring information in security advisories.

CVSS helps communicate vulnerability severity using standard metrics such as:

  • Attack Vector
  • Attack Complexity
  • Privileges Required
  • User Interaction
  • Impact to Confidentiality
  • Impact to Integrity
  • Impact to Availability
  • Exploit maturity or threat context, where applicable
  • Environmental or deployment-specific considerations, where applicable

A Ray advisory may include:

CVSS v3.1 Base Score: 8.8 High
CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Or:

CVSS v4.0 Base Score: 9.3 Critical
CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Where appropriate, Ray may include both CVSS v3.1 and CVSS v4.0 to support customer vulnerability management workflows.

 

Supported Products

Security advisories generally apply to supported Ray products and versions.

Ray Secure Innovations prioritizes vulnerability remediation for products that are within their supported lifecycle.

Product Areas Covered

Product Area Advisory Coverage
SD-WAN Controllers, edge appliances, tunnel management, policy engines, routing features
Firewalls Firewall appliances, rule processing, NAT, inspection, management plane
VPN Solutions IPsec, SSL VPN, remote access VPN, site-to-site VPN, tunnel handling
Secure Gateways Gateway services, forwarding plane, access enforcement, management plane
Cloud Management Platform Cloud portal, APIs, device onboarding, orchestration, tenant management
Embedded Linux Appliances Appliance OS, system services, update mechanism, local management
Firmware Firmware images, upgrade packages, boot process, device services
APIs Public APIs, management APIs, authentication and authorization controls
Networking Software Routing, switching, policy, telemetry, controller, and agent components

 

Product Area Advisory Coverage
Virtual Appliances VM images, virtual network/security devices, cloud deployment images
Containerized Services Ray-maintained service containers and deployment images
Future Products New Ray networking and cybersecurity products

End-of-Life Products

Products that have reached end-of-life or end-of-support may not receive security updates. Ray may still publish advisories for end-of-life products when there is significant customer risk, active exploitation, or impact to supported products.

 

Advisory Archive

The table below shows the recommended structure for Ray security advisories.

ImportantThe advisories below are fictional examples for webpage formatting only. They must not be published as real advisories unless replaced with actual Ray advisory data.

 

Latest Security Advisories

Advisory ID Publication Date Product Severity CVSS Score CVE Status Fixed Version
RAY-2026-0002 2026-07-01 Ray Secure Gateway High 8.2 CVE-2026-0002 Fixed GatewayOS 4.8.1
RAY-2026-0003 2026-07-01 Ray SD-WAN Edge Medium 6.5 CVE-2026-0003 Mitigation Available SD-WAN Edge 7.2.4
RAY-2026-0004 2026-07-01 Ray Firewall Appliance High 7.8 CVE-2026-0004 Fixed FirewallOS 6.1.3
RAY-2026-0005 2026-07-01 Ray VPN Service Medium 5.9 CVE-2026-0005 Under Investigation Pending
RAY-2026-0006 2026-07-01 Ray Virtual Appliance Low 3.7 None Fixed VA Image 3.3.2

 

Advisory Status Definitions

Status Meaning
Fixed A fix is available in a released version
Mitigation Available No complete fix is available yet, but mitigation guidance is available
Workaround Available Temporary workaround is available
Under Investigation Ray is actively investigating the issue
Not Affected Ray has determined the product is not affected
No Fix Planned No fix is planned, usually due to EOL status or risk acceptance
Superseded Advisory has been replaced by a newer advisory
Updated Advisory has been revised after initial publication

 

Search and Filter Recommendations

Ray should implement search and filtering capabilities to help customers quickly identify relevant advisories.

Recommended filters:

Filter Purpose
Advisory ID Search by Ray advisory number
CVE ID Search by CVE
Product Filter advisories by affected product
Severity Filter by Critical, High, Medium, Low, Informational
CVSS Score Filter by score range
Publication Date Filter by date range
Last Updated Identify recently updated advisories
Status Filter by fixed, mitigation available, under investigation, etc.
Fixed Version Search by remediation version
Affected Version Identify advisories affecting a specific version
CWE Search by weakness type
Exploitation Status Filter by active exploitation, public exploit, or no known exploitation

Recommended Search Fields

The advisories page should support keyword search across:

  • Advisory title
  • Advisory ID
  • CVE ID
  • Product name
  • Affected version
  • Fixed version
  • CVSS vector
  • CWE
  • Vulnerability summary
  • Technical description
  • Mitigation guidance
  • References

 

RSS and Email Notifications

Ray Secure Innovations recommends providing customer notification options for new and updated security advisories.

Recommended Notification Channels

Channel Purpose
RSS Feed Machine-readable advisory updates
Email Subscription Customer and partner advisory alerts
Support Portal Notifications Authenticated customer notifications

 

Channel Purpose
Cloud Notifications In-product customer alerts
Release Notes Product-specific remediation information
API Feed Automated vulnerability management integration

Email Notification Categories

Customers should be able to subscribe to:

  • All Ray security advisories.
  • Critical and High advisories only.
  • Product-specific advisories.
  • Cloud platform advisories.
  • Firmware advisories.
  • Virtual appliance advisories.
  • API and developer platform advisories.

 

Security Contact

To report a suspected vulnerability or ask a question about a Ray security advisory, contact Ray Product Security.

Contact Purpose Contact
Vulnerability reports rsirt@ray.life
PSIRT coordination rsirt@ray.life
Security advisory questions sect@ray.life
Customer support https://tac.ray.life
Vulnerability Disclosure Policy https://www.ray.life/security/disclosure-policy
security.txt https://www.ray.life/.well-known/security.txt

 

Urgent ReportsFor suspected active exploitation, exposed credentials, remote unauthenticated compromise, or widespread customer impact, include URGENT SECURITY REPORT in the email subject line.

 

Responsible Disclosure Reference

Ray Secure Innovations encourages responsible security research and coordinated vulnerability disclosure.

Researchers should review the Ray Vulnerability Disclosure Policy before submitting reports.

Vulnerability Disclosure Policy:

https://www.ray.life/security/disclosure-policy

Reports should include affected product, affected version, technical description, reproduction steps, proof of concept, impact, and disclosure status.

Ray aims to acknowledge vulnerability reports within 3 business days and provide updates during active investigation where practical.

 

Advisory Publication Lifecycle

flowchart TD
A[Potential vulnerability reported or discovered] –> B[PSIRT intake]
B –> C[Initial triage]
C –> D{In scope for Ray?}
D — No –> E[Close, redirect, or document]
D — Yes –> F[Technical validation]
F –> G{Valid vulnerability?}
G — No –> H[Close as duplicate, informational, or not reproducible]
G — Yes –> I[Severity assessment using CVSS and risk analysis]
I –> J[Identify affected products and versions]
J –> K[Develop fix, mitigation, or workaround]
K –> L[Security verification and QA]
L –> M{CVE applicable?}
M — Yes –> N[Assign or request CVE ID]
M — No –> O[Prepare advisory without CVE]
N –> P[Draft advisory]
O –> P
P –> Q[Legal, support, engineering, and communications review]
Q –> R[Coordinate disclosure date]
R –> S[Publish advisory]
S –> T[Notify customers and partners]
T –> U[Monitor feedback and update advisory if needed]

 

Vulnerability Remediation Process

flowchart LR
A[Validated Vulnerability] –> B[Assign Engineering Owner]
B –> C[Root Cause Analysis]
C –> D[Fix Strategy]
D –> E[Patch Development]
E –> F[Security Review]
F –> G[Regression Testing]
G –> H[Release Candidate]
H –> I[Release Approval]
I –> J[Fixed Version Published]
J –> K[Advisory Published]
K –> L[Customer Upgrade or Mitigation]
L –> M[Post-Release Monitoring]
M –> N[Secure Development Improvements]

 

Customer Notification Process Recommendations

Ray should maintain a documented customer notification process for security advisories.

Recommended Process

  1. Classify advisory severity.
  2. Identify affected customers, products, versions, and deployment models.
  3. Prepare customer-facing advisory content.
  4. Prepare support scripts and escalation guidance.
  5. Notify registered security contacts.
  6. Publish advisory on the public advisory page.
  7. Publish or update release notes.
  8. Notify partners, resellers, and managed service providers where appropriate.
  9. Track customer questions, upgrade adoption, and advisory updates.

 

Notification Priority

Severity Recommended Notification
Critical Immediate customer notification, public advisory, support readiness, direct outreach for affected enterprise customers
High Email notification, advisory publication, support portal notification
Medium Advisory publication, release notes, optional email notification
Low Advisory publication or release notes
Informational Documentation or security notice

 

Version Management Recommendations

Ray should maintain clear affected-version and fixed-version information in every advisory.

Recommended Version Rules

  • Use exact affected version ranges where possible.
  • Avoid ambiguous wording such as “all older versions” unless technically accurate.
  • Clearly state fixed versions.
  • Identify whether cloud services have already been remediated.
  • Identify whether customer-managed products require manual upgrade.
  • Identify whether firmware, VM image, package, or container image updates are required.
  • Document whether a workaround fully or partially mitigates the issue.
  • Track superseded fixes and advisory revisions.

 

Example Version Format

Affected:
Ray FirewallOS 6.0.0 through 6.1.2Fixed:
Ray FirewallOS 6.1.3 and later
Ray FirewallOS 6.0.8 LTS and later

 

Archived Advisories Recommendations

Ray should maintain older advisories in a searchable archive.

Archive Rules

  • Do not delete old advisories unless legally required.
  • Mark superseded advisories clearly.
  • Preserve original publication date and revision history.
  • Add banners for advisories affecting end-of-life products.
  • Keep advisory URLs stable.
  • Maintain redirects if advisory URLs change.
  • Ensure advisories remain indexable by search engines and vulnerability databases.
  • Support machine-readable feeds where possible.

 

Archive Status Labels

Archive Label Meaning
Active Advisory affects currently supported products
Archived Advisory is retained for historical reference
Superseded Advisory has been replaced by a newer advisory
EOL Product Advisory affects only end-of-life products
Updated Advisory was revised after original publication

 

Advisory Update Policy

Ray may update published advisories when new information becomes available.

Advisory updates may include:

  • Newly affected products or versions.
  • Additional fixed versions.
  • Updated CVSS score or vector.
  • Updated CWE classification.
  • New exploitation information.
  • Additional mitigation guidance.
  • Updated upgrade instructions.
  • Reporter credit updates.
  • Reference updates.
  • Clarifications or corrections.
  • Revision history updates.

 

Advisory Revision Rules

Each advisory should include a revision history table.

Revision Type Example
Initial Publication Advisory first published
Minor Update Typographical correction or clarification
Technical Update Affected version, fix version, or mitigation changed
Severity Update CVSS score or severity changed
Exploitation Update Known exploitation status changed
Superseded Advisory replaced by another advisory

 

Reusable Security Advisory Template

Use this template for each Ray security advisory.

Advisory Title

Example:

Improper Authorization Vulnerability in Ray Cloud Controller

 

Advisory Metadata

Field Value
Advisory ID RAY-2026-0001
CVE ID CVE-2026-23456 or Pending or Not Assigned
CWE CWE-287: Improper Authentication
CVSS Score 9.1 Critical
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity Critical
Publication Date 2026-07-01
Last Updated 2026-07-01
Advisory Status Fixed
Exploitation Status Not Known

 

Affected Products

Product Affected Versions Fixed Versions Status
Ray Cloud Controller Cloud Controller 20.7.0 through 20.8.0 Cloud Controller 20.9.1 and later Fixed

 

Vulnerability Summary

A critical authentication validation vulnerability in Ray Cloud Controller and related management services could allow an unauthenticated remote attacker to bypass authentication under specific conditions and gain unauthorized access to administrative management functions.

Successful exploitation could allow an attacker to view or modify device configuration, access limited tenant metadata, or perform unauthorized management actions depending on the affected deployment and product configuration.

Technical Description

Incomplete validation of authentication state during certain API request flows used by the management interface

Include:

  • Affected component.
  • Vulnerability class.
  • Required privileges.
  • Required network access.
  • Required user interaction.
  • Affected configuration.
  • Security boundary affected.
  • Conditions required for exploitation.
  • Whether the vulnerability affects default deployments.

Avoid publishing exploit code or unnecessary weaponized details.

Impact

Successful exploitation could allow unauthorized access to management functions, configuration data, or tenant metadata depending on deployment configuration and exposed interfaces.

Potential impact examples:

  • Unauthorized access to configuration data.
  • Privilege escalation.
  • Management plane compromise.
  • Device configuration modification.
  • Remote code execution.
  • Security policy bypass.
  • Service disruption.
  • Tenant isolation failure.
  • Sensitive information disclosure.

 

Attack Vector

Factor Value
Network Access Required Network
Authentication Required Low Privileges
User Interaction Required Yes
Default Configuration Affected Conditional
Exploit Complexity High

 

Exploitation Status

State whether Ray is aware of exploitation.

Recommended wording:

Ray recommends that customers upgrade to Ray FirewallOS 6.1.3 or later. This release contains a fix for the vulnerability described in this advisory.

Or:

Ray Secure Innovations is not aware of a complete workaround for this vulnerability. Customers should upgrade to a fixed version as soon as possible.

 

Mitigation

Ray will provide temporary mitigation guidance if available.

Examples:

  • Restrict management interface access to trusted networks.
  • Disable affected feature temporarily.
  • Apply access control rules.
  • Rotate affected credentials.
  • Enforce multi-factor authentication.
  • Block vulnerable endpoint at gateway or firewall.
  • Disable external exposure of affected API.
  • Apply recommended Nebula policy changes.

 

Resolution

Ray will provide fixed version and recommended customer action.

Example:

Ray recommends that customers upgrade to Ray FirewallOS 6.1.3 or later. This release contains a fix for the vulnerability described in this advisory.

 

Upgrade Instructions

Add product-specific upgrade instructions or link to release documentation.

Recommended structure:

  1. Review affected versions.
  2. Confirm backup of current configuration.
  3. Download fixed version from official Ray portal.
  4. Validate image checksum or signature.
  5. Apply update during approved maintenance window.
  6. Reboot appliance if required.
  7. Confirm fixed version after upgrade.
  8. Review logs for errors.
  9. Contact Ray Support if upgrade fails.

 

Workarounds

Ray will add workarounds if available.

If no workaround is available:

Ray Secure Innovations is not aware of a complete workaround for this vulnerability. Customers should upgrade to a fixed version as soon as possible.

 

Detection Guidance

Ray will add logs, commands, indicators, or methods customers can use to identify exposure or exploitation.

Examples:

  • Review authentication logs.
  • Review API access logs.
  • Review management plane access logs.
  • Check for unexpected configuration changes.
  • Verify administrative user activity.
  • Review cloud audit logs.
  • Review firmware upgrade logs.
  • Search for suspicious requests to affected endpoints.

 

Indicators of Compromise

Ray Secure Innovations will provide IOCs if found with any vulnerabilities.

If no IOCs are known:

Ray Secure Innovations is not aware of specific indicators of compromise associated with this vulnerability at the time of publication.

 

Credits

Credit the researcher if applicable and approved.

Example:

Ray Secure Innovations thanks [Researcher Name / Organization] for responsibly reporting this vulnerability.

If no public credit:

Ray Secure Innovations thanks the reporting party for working with us through coordinated disclosure.

 

Revision History

Version Date Description
1.0 01/07/2026 Initial publication

 

FAQ

What is a Ray security advisory?

A Ray security advisory is an official public notice describing a validated security vulnerability or security issue affecting Ray products or services.

Does every Ray advisory have a CVE ID?

No. Some advisories may not receive a CVE ID if the issue does not meet CVE eligibility criteria, is a hardening recommendation, affects only unsupported products, or is already covered by another CVE.

Can one advisory contain multiple CVEs?

Yes. If multiple related vulnerabilities affect the same product, component, release, or remediation package, Ray may publish them in a single advisory.

How should customers prioritize advisories?

Customers should prioritize based on severity, CVSS score, product exposure, deployment model, exploitability, available mitigations, and whether exploitation is known.

What should customers do when a product is listed as affected?

Customers should review the affected version range, apply the fixed version or mitigation, review detection guidance, and contact Ray Support if assistance is required.

Are cloud services fixed automatically?

For Ray-managed cloud services, Ray may deploy fixes directly. Customer action may still be required for connected appliances, agents, APIs, integrations, or configuration changes.

How are researchers credited?

Ray may credit researchers who responsibly report validated vulnerabilities and follow Ray’s Vulnerability Disclosure Policy, subject to legal, privacy, safety, and coordination requirements.

Where should vulnerabilities be reported?

Vulnerabilities should be reported to Ray Product Security at:

rsirt@ray.life

 

Glossary

Term Meaning
Advisory Public notice describing a security issue, affected products, impact, and remediation
Affected Version Product version confirmed to contain the vulnerability
Attack Vector Method or path an attacker may use to exploit a vulnerability
CNA CVE Numbering Authority; an organization authorized to assign CVE IDs within a defined scope
CVE Common Vulnerabilities and Exposures identifier for publicly disclosed cybersecurity vulnerabilities
CVSS Common Vulnerability Scoring System used to communicate vulnerability severity
CWE Common Weakness Enumeration used to classify weakness types
EOL End of Life; product or version no longer supported
EOS End of Support; product or version no longer receiving support or updates
Exploitation Status Whether exploitation is known, public, active, or not observed
Fixed Version Product version containing remediation
Mitigation Action that reduces risk without fully removing the vulnerability
PSIRT Product Security Incident Response Team
Remediation Patch, upgrade, configuration change, or other action that resolves the vulnerability
security.txt Machine-readable file that provides security contact and disclosure information
Severity Rating that communicates vulnerability impact and urgency

 

Term Meaning
Workaround Temporary action customers can take until a full fix is available