All incidents

CISA adds Ray-Project Ray code injection flaw (CVE-2025-62593) to KEV catalog

vulnerabilityopenAug 17, 2026 — Aug 17, 2026

ON 17 August 2026 the Cybersecurity and Infrastructure Security Agency added CVE‑2025‑62593 to its Known Exploited Vulnerabilities catalogue after confirming that the Ray‑Project Ray code injection flaw is being exploited in the wild. The entry notes that the vulnerability permits remote code execution when a user loads malicious content through Firefox or Safari while interacting with a Ray instance. Federal agencies are now required to prioritise patching under Binding Operational Directive 26‑04. CISA announced the addition.

CVE‑2025‑62593 is described as a code injection vulnerability in the Ray framework that lets an attacker run arbitrary code on a compromised host. Exploitation relies on luring a developer to visit a specially crafted web page that triggers the flaw via the browser’s JavaScript engine, affecting both Firefox and Safari. Although the National Vulnerability Database currently lists a CVSS score of 0.0, CISA has marked the issue as critical due to the observed active use. Further details are available in the KEV entry. Read the KEV catalogue note.

Security researchers have not yet tied the activity to a specific threat actor, but the pattern matches campaigns that target development environments to gain a foothold for later lateral movement. Because Ray is widely used for machine learning workloads and distributed computing, any organisation that runs the framework internally or in containers could be exposed if developers browse untrusted sites. The binding directive gives federal civilian agencies a deadline to remediate, prompting a broader push for vulnerability management across critical sectors.

Defenders should first verify whether any Ray deployments are reachable from the internet and restrict access to trusted networks only. Applying the latest security updates from the Ray project, once they are released, is essential; in the meantime, consider disabling JavaScript for internal Ray interfaces or using browser isolation techniques. Monitoring web proxy logs for unexpected requests to Ray endpoints can help detect exploitation attempts, and endpoint detection tools should be tuned to look for unusual process spawning from browser contexts.

Organisations are encouraged to subscribe to CISA’s KEV feed to receive timely updates on similar threats and to review their asset inventories for any unmanaged Ray instances. Sharing indicators of compromise with information sharing and analysis centres can improve collective defence, while regular penetration testing of internal developer tools helps catch configuration gaps before they are exploited. Staying vigilant and patching promptly remain the most effective ways to reduce risk.

Intelligence briefing updated Aug 17, 2026

CVE-2025-62593 KEV
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline