Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-18 ยท updated: 2026-08-18 ยท tags: [incident, kev, advisory, ray, ai-ml, government, sector-government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true

CISA Adds Ray-Project Ray Code Injection Flaw to Known Exploited Vulnerabilities

  • Source: CISA
  • Date: 2026-08-17
  • Reliability: Tier 1/4 โ€” Official / First-party
  • Entity: CISA KEV catalogue / Ray-Project Ray

Summary

CISA added CVE-2025-62593, a code-injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-17 with a remediation due date of 2026-08-20, signalling confirmed exploitation in the wild. Ray is widely used for AI/ML orchestration and distributed workloads.

Key Facts

  • CVE-2025-62593 โ€” Ray code injection; added to KEV 17 August 2026
  • Remediation due 20 August 2026
  • Continues a week of KEV activity (Cisco ASA/FTD, Windows WinSock, Metabase)
  • Reinforces the two-week BOD 26-04 federal patch directive

Sector

Government โ€” Official KEV/advisory action by CISA.

Source

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

Reliability

Tier 1 โ€” Official government source.

Date

2026-08-17

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-18