ON August 17, 2026, CISA added a new vulnerability, CVE-2025-62593, related to the Ray-Project Ray Code Injection, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This vulnerability represents a significant threat to federal entities. The Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk vulnerabilities listed in the KEV Catalog.
CISA encourages all organizations to adopt a risk-based approach to vulnerability management. Additional vulnerabilities can be nominated for inclusion in the KEV Catalog through a specified form.