Security Advisories
Ray Secure Innovations Security Advisories
Official Security Advisory Repository for Ray Secure Innovations Products and Services
Overview
Ray Secure Innovations publishes security advisories to help customers, partners, security researchers, and the broader cybersecurity community understand security vulnerabilities affecting Ray products and services.
This page serves as the official public repository for Ray Secure Innovations security advisories, including vulnerabilities affecting Ray networking devices, security, cloud management, firmware, virtual appliance, API, and other Ray products.
Ray Secure Innovations develops enterprise networking and cybersecurity technologies, including:
- SD-WAN
- Firewalls
- VPN solutions
- Secure Gateways
- HSIA
- Cloud Controller
- Embedded Linux appliances
- APIs
- Networking software
- Firmware
- Virtual appliances
- Future networking and security products
| Security NoticeRay Secure Innovations recommends that customers regularly review this page, subscribe to advisory notifications, and keep Ray products updated to supported and fixed versions. |
Purpose
The purpose of this Security Advisories page is to:
- Provide a central public source for Ray security advisories.
- Help customers identify affected products and versions.
- Provide remediation, mitigation, workaround, and upgrade guidance.
- Communicate CVE identifiers, CVSS scores, CWE classifications, and severity ratings where applicable.
- Support coordinated vulnerability disclosure.
- Support Ray Secure Innovations’ vulnerability management and CVE publication process.
- Provide a mature public disclosure source suitable for Ray’s current or future role as a CVE Numbering Authority.
How Security Advisories Are Published
Ray Secure Innovations publishes a security advisory when a validated vulnerability affects Ray products or services and customer awareness or action is required.
Advisories may be published for vulnerabilities affecting:
- Ray-developed software or firmware.
- Ray-managed cloud services.
- Ray Cloud Management Platform.
- Ray SD-WAN, firewall, VPN, HSIA and secure gateway products.
- Ray APIs and web management interfaces.
- Ray virtual appliances and containerized services.
- Ray-maintained open-source components.
- Third-party or open-source components when they affect Ray products and require customer action.
Ray may publish an advisory when:
- A vulnerability has been validated.
- Affected products and versions have been identified.
- Severity and customer impact have been assessed.
- A fix, patch, upgrade, mitigation, or workaround is available.
- CVE assignment has been completed or requested, where applicable.
- Coordinated disclosure requirements have been considered.
- Customer guidance is ready for publication.
Ray may also publish an advisory before a complete fix is available when customer protection requires early notification, including cases involving active exploitation, public exploit availability, or significant customer risk.
Advisory Numbering Scheme
Ray Secure Innovations security advisories use the following numbering format:
| RAY-YYYY-NNNN |
Where:
| Field | Meaning | Example |
| RAY | Ray Secure Innovations advisory prefix | RAY |
| YYYY | Year of initial advisory publication | 2026 |
| NNNN | Sequential advisory number for that year | 0001 |
Example
| RAY-2026-0001 |
This represents the first Ray security advisory published in 2026.
| NoteAdvisory IDs are Ray-specific identifiers. They are separate from CVE IDs. |
Relationship Between Advisory IDs and CVEs
A Ray advisory ID and a CVE ID serve different purposes.
| Identifier | Purpose | Example |
| Ray Advisory ID | Ray’s internal and public advisory tracking identifier | RAY-2026-0001 |
| Identifier | Purpose | Example |
| CVE ID | Globally recognized vulnerability identifier | CVE-2026-12345 |
| CWE ID | Weakness classification describing the vulnerability type | CWE-78 |
| CVSS Vector | Standardized vulnerability severity vector | CVSS:3.1/… or CVSS:4.0/… |
One Ray advisory may reference:
- One CVE.
- Multiple CVEs.
- No CVE, if the issue does not meet CVE eligibility criteria.
- A third-party CVE, if the vulnerability originates in a dependency or upstream component.
CNA Status Wording
| Before Ray becomes an approved CNA: Ray Secure Innovations may request CVE assignment through the appropriate CVE Numbering Authority, Root CNA, or coordination body where applicable. |
| After Ray becomes an approved CNA: Ray Secure Innovations is a CVE Numbering Authority and may assign CVE IDs for vulnerabilities within its approved CNA scope. |
Severity Classification
Ray Secure Innovations uses severity ratings to help customers prioritize remediation.
Severity is generally based on CVSS scoring, product-specific risk, deployment exposure, exploitability, impact, and whether exploitation is known or likely.
| Severity | CVSS Score Range | General Meaning |
| Critical | 9.0 – 10.0 | Vulnerability may allow severe compromise such as remote code execution, authentication bypass, complete system compromise, or major cloud tenant isolation failure |
| High | 7.0 – 8.9 | Vulnerability may allow significant compromise, privilege escalation, sensitive data exposure, security control bypass, or major service impact |
| Medium | 4.0 – 6.9 | Vulnerability may require specific conditions, user interaction, authentication, or limited access but still creates meaningful security risk |
| Low | 0.1 – 3.9 | Vulnerability has limited impact, difficult exploitability, or strong mitigating conditions |
| Informational | N/A | Security notice, hardening recommendation, or non-vulnerability security information |
| ImportantCVSS score is an important severity input, but Ray may adjust customer remediation priority based on active exploitation, product exposure, customer impact, and available mitigations. |
| exposure, default configuration, mitigations, and operational impact. |
CVSS Explanation
Ray Secure Innovations may publish CVSS v3.1 and/or CVSS v4.0 scoring information in security advisories.
CVSS helps communicate vulnerability severity using standard metrics such as:
- Attack Vector
- Attack Complexity
- Privileges Required
- User Interaction
- Impact to Confidentiality
- Impact to Integrity
- Impact to Availability
- Exploit maturity or threat context, where applicable
- Environmental or deployment-specific considerations, where applicable
A Ray advisory may include:
| CVSS v3.1 Base Score: 8.8 High CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Or:
| CVSS v4.0 Base Score: 9.3 Critical CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Where appropriate, Ray may include both CVSS v3.1 and CVSS v4.0 to support customer vulnerability management workflows.
Supported Products
Security advisories generally apply to supported Ray products and versions.
Ray Secure Innovations prioritizes vulnerability remediation for products that are within their supported lifecycle.
Product Areas Covered
| Product Area | Advisory Coverage |
| SD-WAN | Controllers, edge appliances, tunnel management, policy engines, routing features |
| Firewalls | Firewall appliances, rule processing, NAT, inspection, management plane |
| VPN Solutions | IPsec, SSL VPN, remote access VPN, site-to-site VPN, tunnel handling |
| Secure Gateways | Gateway services, forwarding plane, access enforcement, management plane |
| Cloud Management Platform | Cloud portal, APIs, device onboarding, orchestration, tenant management |
| Embedded Linux Appliances | Appliance OS, system services, update mechanism, local management |
| Firmware | Firmware images, upgrade packages, boot process, device services |
| APIs | Public APIs, management APIs, authentication and authorization controls |
| Networking Software | Routing, switching, policy, telemetry, controller, and agent components |
| Product Area | Advisory Coverage |
| Virtual Appliances | VM images, virtual network/security devices, cloud deployment images |
| Containerized Services | Ray-maintained service containers and deployment images |
| Future Products | New Ray networking and cybersecurity products |
End-of-Life Products
Products that have reached end-of-life or end-of-support may not receive security updates. Ray may still publish advisories for end-of-life products when there is significant customer risk, active exploitation, or impact to supported products.
Advisory Archive
The table below shows the recommended structure for Ray security advisories.
| ImportantThe advisories below are fictional examples for webpage formatting only. They must not be published as real advisories unless replaced with actual Ray advisory data. |
Latest Security Advisories
| Advisory ID | Publication Date | Product | Severity | CVSS Score | CVE | Status | Fixed Version |
| RAY-2026-0002 | 2026-07-01 | Ray Secure Gateway | High | 8.2 | CVE-2026-0002 | Fixed | GatewayOS 4.8.1 |
| RAY-2026-0003 | 2026-07-01 | Ray SD-WAN Edge | Medium | 6.5 | CVE-2026-0003 | Mitigation Available | SD-WAN Edge 7.2.4 |
| RAY-2026-0004 | 2026-07-01 | Ray Firewall Appliance | High | 7.8 | CVE-2026-0004 | Fixed | FirewallOS 6.1.3 |
| RAY-2026-0005 | 2026-07-01 | Ray VPN Service | Medium | 5.9 | CVE-2026-0005 | Under Investigation | Pending |
| RAY-2026-0006 | 2026-07-01 | Ray Virtual Appliance | Low | 3.7 | None | Fixed | VA Image 3.3.2 |
Advisory Status Definitions
| Status | Meaning |
| Fixed | A fix is available in a released version |
| Mitigation Available | No complete fix is available yet, but mitigation guidance is available |
| Workaround Available | Temporary workaround is available |
| Under Investigation | Ray is actively investigating the issue |
| Not Affected | Ray has determined the product is not affected |
| No Fix Planned | No fix is planned, usually due to EOL status or risk acceptance |
| Superseded | Advisory has been replaced by a newer advisory |
| Updated | Advisory has been revised after initial publication |
Search and Filter Recommendations
Ray should implement search and filtering capabilities to help customers quickly identify relevant advisories.
Recommended filters:
| Filter | Purpose |
| Advisory ID | Search by Ray advisory number |
| CVE ID | Search by CVE |
| Product | Filter advisories by affected product |
| Severity | Filter by Critical, High, Medium, Low, Informational |
| CVSS Score | Filter by score range |
| Publication Date | Filter by date range |
| Last Updated | Identify recently updated advisories |
| Status | Filter by fixed, mitigation available, under investigation, etc. |
| Fixed Version | Search by remediation version |
| Affected Version | Identify advisories affecting a specific version |
| CWE | Search by weakness type |
| Exploitation Status | Filter by active exploitation, public exploit, or no known exploitation |
Recommended Search Fields
The advisories page should support keyword search across:
- Advisory title
- Advisory ID
- CVE ID
- Product name
- Affected version
- Fixed version
- CVSS vector
- CWE
- Vulnerability summary
- Technical description
- Mitigation guidance
- References
RSS and Email Notifications
Ray Secure Innovations recommends providing customer notification options for new and updated security advisories.
Recommended Notification Channels
| Channel | Purpose |
| RSS Feed | Machine-readable advisory updates |
| Email Subscription | Customer and partner advisory alerts |
| Support Portal Notifications | Authenticated customer notifications |
| Channel | Purpose |
| Cloud Notifications | In-product customer alerts |
| Release Notes | Product-specific remediation information |
| API Feed | Automated vulnerability management integration |
Email Notification Categories
Customers should be able to subscribe to:
- All Ray security advisories.
- Critical and High advisories only.
- Product-specific advisories.
- Cloud platform advisories.
- Firmware advisories.
- Virtual appliance advisories.
- API and developer platform advisories.
Security Contact
To report a suspected vulnerability or ask a question about a Ray security advisory, contact Ray Product Security.
| Contact Purpose | Contact |
| Vulnerability reports | rsirt@ray.life |
| PSIRT coordination | rsirt@ray.life |
| Security advisory questions | sect@ray.life |
| Customer support | https://tac.ray.life |
| Vulnerability Disclosure Policy | https://www.ray.life/security/disclosure-policy |
| security.txt | https://www.ray.life/.well-known/security.txt |
| Urgent ReportsFor suspected active exploitation, exposed credentials, remote unauthenticated compromise, or widespread customer impact, include URGENT SECURITY REPORT in the email subject line. |
Responsible Disclosure Reference
Ray Secure Innovations encourages responsible security research and coordinated vulnerability disclosure.
Researchers should review the Ray Vulnerability Disclosure Policy before submitting reports.
Vulnerability Disclosure Policy:
https://www.ray.life/security/disclosure-policy
Reports should include affected product, affected version, technical description, reproduction steps, proof of concept, impact, and disclosure status.
Ray aims to acknowledge vulnerability reports within 3 business days and provide updates during active investigation where practical.
Advisory Publication Lifecycle
| flowchart TD A[Potential vulnerability reported or discovered] –> B[PSIRT intake] B –> C[Initial triage] C –> D{In scope for Ray?} D — No –> E[Close, redirect, or document] D — Yes –> F[Technical validation] F –> G{Valid vulnerability?} G — No –> H[Close as duplicate, informational, or not reproducible] G — Yes –> I[Severity assessment using CVSS and risk analysis] I –> J[Identify affected products and versions] J –> K[Develop fix, mitigation, or workaround] K –> L[Security verification and QA] L –> M{CVE applicable?} M — Yes –> N[Assign or request CVE ID] M — No –> O[Prepare advisory without CVE] N –> P[Draft advisory] O –> P P –> Q[Legal, support, engineering, and communications review] Q –> R[Coordinate disclosure date] R –> S[Publish advisory] S –> T[Notify customers and partners] T –> U[Monitor feedback and update advisory if needed] |
Vulnerability Remediation Process
| flowchart LR A[Validated Vulnerability] –> B[Assign Engineering Owner] B –> C[Root Cause Analysis] C –> D[Fix Strategy] D –> E[Patch Development] E –> F[Security Review] F –> G[Regression Testing] G –> H[Release Candidate] H –> I[Release Approval] I –> J[Fixed Version Published] J –> K[Advisory Published] K –> L[Customer Upgrade or Mitigation] L –> M[Post-Release Monitoring] M –> N[Secure Development Improvements] |
Customer Notification Process Recommendations
Ray should maintain a documented customer notification process for security advisories.
Recommended Process
- Classify advisory severity.
- Identify affected customers, products, versions, and deployment models.
- Prepare customer-facing advisory content.
- Prepare support scripts and escalation guidance.
- Notify registered security contacts.
- Publish advisory on the public advisory page.
- Publish or update release notes.
- Notify partners, resellers, and managed service providers where appropriate.
- Track customer questions, upgrade adoption, and advisory updates.
Notification Priority
| Severity | Recommended Notification |
| Critical | Immediate customer notification, public advisory, support readiness, direct outreach for affected enterprise customers |
| High | Email notification, advisory publication, support portal notification |
| Medium | Advisory publication, release notes, optional email notification |
| Low | Advisory publication or release notes |
| Informational | Documentation or security notice |
Version Management Recommendations
Ray should maintain clear affected-version and fixed-version information in every advisory.
Recommended Version Rules
- Use exact affected version ranges where possible.
- Avoid ambiguous wording such as “all older versions” unless technically accurate.
- Clearly state fixed versions.
- Identify whether cloud services have already been remediated.
- Identify whether customer-managed products require manual upgrade.
- Identify whether firmware, VM image, package, or container image updates are required.
- Document whether a workaround fully or partially mitigates the issue.
- Track superseded fixes and advisory revisions.
Example Version Format
| Affected: Ray FirewallOS 6.0.0 through 6.1.2Fixed: Ray FirewallOS 6.1.3 and later Ray FirewallOS 6.0.8 LTS and later |
Archived Advisories Recommendations
Ray should maintain older advisories in a searchable archive.
Archive Rules
- Do not delete old advisories unless legally required.
- Mark superseded advisories clearly.
- Preserve original publication date and revision history.
- Add banners for advisories affecting end-of-life products.
- Keep advisory URLs stable.
- Maintain redirects if advisory URLs change.
- Ensure advisories remain indexable by search engines and vulnerability databases.
- Support machine-readable feeds where possible.
Archive Status Labels
| Archive Label | Meaning |
| Active | Advisory affects currently supported products |
| Archived | Advisory is retained for historical reference |
| Superseded | Advisory has been replaced by a newer advisory |
| EOL Product | Advisory affects only end-of-life products |
| Updated | Advisory was revised after original publication |
Advisory Update Policy
Ray may update published advisories when new information becomes available.
Advisory updates may include:
- Newly affected products or versions.
- Additional fixed versions.
- Updated CVSS score or vector.
- Updated CWE classification.
- New exploitation information.
- Additional mitigation guidance.
- Updated upgrade instructions.
- Reporter credit updates.
- Reference updates.
- Clarifications or corrections.
- Revision history updates.
Advisory Revision Rules
Each advisory should include a revision history table.
| Revision Type | Example |
| Initial Publication | Advisory first published |
| Minor Update | Typographical correction or clarification |
| Technical Update | Affected version, fix version, or mitigation changed |
| Severity Update | CVSS score or severity changed |
| Exploitation Update | Known exploitation status changed |
| Superseded | Advisory replaced by another advisory |
Reusable Security Advisory Template
Use this template for each Ray security advisory.
Advisory Title
Example:
| Improper Authorization Vulnerability in Ray Cloud Controller |
Advisory Metadata
| Field | Value |
| Advisory ID | RAY-2026-0001 |
| CVE ID | CVE-2026-23456 or Pending or Not Assigned |
| CWE | CWE-287: Improper Authentication |
| CVSS Score | 9.1 Critical |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | Critical |
| Publication Date | 2026-07-01 |
| Last Updated | 2026-07-01 |
| Advisory Status | Fixed |
| Exploitation Status | Not Known |
Affected Products
| Product | Affected Versions | Fixed Versions | Status |
| Ray Cloud Controller | Cloud Controller 20.7.0 through 20.8.0 | Cloud Controller 20.9.1 and later | Fixed |
Vulnerability Summary
A critical authentication validation vulnerability in Ray Cloud Controller and related management services could allow an unauthenticated remote attacker to bypass authentication under specific conditions and gain unauthorized access to administrative management functions.
Successful exploitation could allow an attacker to view or modify device configuration, access limited tenant metadata, or perform unauthorized management actions depending on the affected deployment and product configuration.
Technical Description
Incomplete validation of authentication state during certain API request flows used by the management interface
Include:
- Affected component.
- Vulnerability class.
- Required privileges.
- Required network access.
- Required user interaction.
- Affected configuration.
- Security boundary affected.
- Conditions required for exploitation.
- Whether the vulnerability affects default deployments.
Avoid publishing exploit code or unnecessary weaponized details.
Impact
Successful exploitation could allow unauthorized access to management functions, configuration data, or tenant metadata depending on deployment configuration and exposed interfaces.
Potential impact examples:
- Unauthorized access to configuration data.
- Privilege escalation.
- Management plane compromise.
- Device configuration modification.
- Remote code execution.
- Security policy bypass.
- Service disruption.
- Tenant isolation failure.
- Sensitive information disclosure.
Attack Vector
| Factor | Value |
| Network Access Required | Network |
| Authentication Required | Low Privileges |
| User Interaction Required | Yes |
| Default Configuration Affected | Conditional |
| Exploit Complexity | High |
Exploitation Status
State whether Ray is aware of exploitation.
Recommended wording:
| Ray recommends that customers upgrade to Ray FirewallOS 6.1.3 or later. This release contains a fix for the vulnerability described in this advisory. |
Or:
| Ray Secure Innovations is not aware of a complete workaround for this vulnerability. Customers should upgrade to a fixed version as soon as possible. |
Mitigation
Ray will provide temporary mitigation guidance if available.
Examples:
- Restrict management interface access to trusted networks.
- Disable affected feature temporarily.
- Apply access control rules.
- Rotate affected credentials.
- Enforce multi-factor authentication.
- Block vulnerable endpoint at gateway or firewall.
- Disable external exposure of affected API.
- Apply recommended Nebula policy changes.
Resolution
Ray will provide fixed version and recommended customer action.
Example:
| Ray recommends that customers upgrade to Ray FirewallOS 6.1.3 or later. This release contains a fix for the vulnerability described in this advisory. |
Upgrade Instructions
Add product-specific upgrade instructions or link to release documentation.
Recommended structure:
- Review affected versions.
- Confirm backup of current configuration.
- Download fixed version from official Ray portal.
- Validate image checksum or signature.
- Apply update during approved maintenance window.
- Reboot appliance if required.
- Confirm fixed version after upgrade.
- Review logs for errors.
- Contact Ray Support if upgrade fails.
Workarounds
Ray will add workarounds if available.
If no workaround is available:
| Ray Secure Innovations is not aware of a complete workaround for this vulnerability. Customers should upgrade to a fixed version as soon as possible. |
Detection Guidance
Ray will add logs, commands, indicators, or methods customers can use to identify exposure or exploitation.
Examples:
- Review authentication logs.
- Review API access logs.
- Review management plane access logs.
- Check for unexpected configuration changes.
- Verify administrative user activity.
- Review cloud audit logs.
- Review firmware upgrade logs.
- Search for suspicious requests to affected endpoints.
Indicators of Compromise
Ray Secure Innovations will provide IOCs if found with any vulnerabilities.
If no IOCs are known:
| Ray Secure Innovations is not aware of specific indicators of compromise associated with this vulnerability at the time of publication. |
Credits
Credit the researcher if applicable and approved.
Example:
| Ray Secure Innovations thanks [Researcher Name / Organization] for responsibly reporting this vulnerability. |
If no public credit:
| Ray Secure Innovations thanks the reporting party for working with us through coordinated disclosure. |
Revision History
| Version | Date | Description |
| 1.0 | 01/07/2026 | Initial publication |
FAQ
What is a Ray security advisory?
A Ray security advisory is an official public notice describing a validated security vulnerability or security issue affecting Ray products or services.
Does every Ray advisory have a CVE ID?
No. Some advisories may not receive a CVE ID if the issue does not meet CVE eligibility criteria, is a hardening recommendation, affects only unsupported products, or is already covered by another CVE.
Can one advisory contain multiple CVEs?
Yes. If multiple related vulnerabilities affect the same product, component, release, or remediation package, Ray may publish them in a single advisory.
How should customers prioritize advisories?
Customers should prioritize based on severity, CVSS score, product exposure, deployment model, exploitability, available mitigations, and whether exploitation is known.
What should customers do when a product is listed as affected?
Customers should review the affected version range, apply the fixed version or mitigation, review detection guidance, and contact Ray Support if assistance is required.
Are cloud services fixed automatically?
For Ray-managed cloud services, Ray may deploy fixes directly. Customer action may still be required for connected appliances, agents, APIs, integrations, or configuration changes.
How are researchers credited?
Ray may credit researchers who responsibly report validated vulnerabilities and follow Ray’s Vulnerability Disclosure Policy, subject to legal, privacy, safety, and coordination requirements.
Where should vulnerabilities be reported?
Vulnerabilities should be reported to Ray Product Security at:
| rsirt@ray.life |
Glossary
| Term | Meaning |
| Advisory | Public notice describing a security issue, affected products, impact, and remediation |
| Affected Version | Product version confirmed to contain the vulnerability |
| Attack Vector | Method or path an attacker may use to exploit a vulnerability |
| CNA | CVE Numbering Authority; an organization authorized to assign CVE IDs within a defined scope |
| CVE | Common Vulnerabilities and Exposures identifier for publicly disclosed cybersecurity vulnerabilities |
| CVSS | Common Vulnerability Scoring System used to communicate vulnerability severity |
| CWE | Common Weakness Enumeration used to classify weakness types |
| EOL | End of Life; product or version no longer supported |
| EOS | End of Support; product or version no longer receiving support or updates |
| Exploitation Status | Whether exploitation is known, public, active, or not observed |
| Fixed Version | Product version containing remediation |
| Mitigation | Action that reduces risk without fully removing the vulnerability |
| PSIRT | Product Security Incident Response Team |
| Remediation | Patch, upgrade, configuration change, or other action that resolves the vulnerability |
| security.txt | Machine-readable file that provides security contact and disclosure information |
| Severity | Rating that communicates vulnerability impact and urgency |
| Term | Meaning |
| Workaround | Temporary action customers can take until a full fix is available |