type: incident ยท created: 2026-08-18 ยท updated: 2026-08-18 ยท tags: [incident, kev, advisory, ray, ai-ml, government, sector-government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true
CISA Adds Ray-Project Ray Code Injection Flaw to Known Exploited Vulnerabilities
- Source: CISA
- Date: 2026-08-17
- Reliability: Tier 1/4 โ Official / First-party
- Entity: CISA KEV catalogue / Ray-Project Ray
Summary
CISA added CVE-2025-62593, a code-injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-17 with a remediation due date of 2026-08-20, signalling confirmed exploitation in the wild. Ray is widely used for AI/ML orchestration and distributed workloads.
Key Facts
- CVE-2025-62593 โ Ray code injection; added to KEV 17 August 2026
- Remediation due 20 August 2026
- Continues a week of KEV activity (Cisco ASA/FTD, Windows WinSock, Metabase)
- Reinforces the two-week BOD 26-04 federal patch directive
Sector
Government โ Official KEV/advisory action by CISA.
Source
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Reliability
Tier 1 โ Official government source.
Date
2026-08-17
Related Pages
- Cve 2025 62593 Ray Code Injection โ CVE detail page
Sources: raw/digests/Cyber-Digest-2026-08-18