THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability, identified as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog. The flaw affects the Ray AI compute engine, specifically versions prior to 2.52.0, which insufficiently protected its dashboard/API against browser attacks. By exploiting this vulnerability, an attacker could execute arbitrary code on a developer's machine through techniques like DNS rebinding.
CISA has ordered federal agencies to address this vulnerability by August 20, 2026, and recommends private organizations also review the catalog for protective measures.