securityaffairs.com 8/18/2026, 9:10:50 AM · external

CISA flags CVE-2025-62593 in Ray AI, orders patch by August

CISA flags CVE-2025-62593 in Ray AI, orders patch by August
Developing story vulnerability 4 articles tracked
CISA adds exploited Ray code injection flaw (CVE-2025-62593) to KEV catalog
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability, identified as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog. The flaw affects the Ray AI compute engine, specifically versions prior to 2.52.0, which insufficiently protected its dashboard/API against browser attacks. By exploiting this vulnerability, an attacker could execute arbitrary code on a developer's machine through techniques like DNS rebinding.

CISA has ordered federal agencies to address this vulnerability by August 20, 2026, and recommends private organizations also review the catalog for protective measures.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline