CVE-2025-62593 โ Ray-Project Ray Code Injection
CVE-2025-62593 is a code-injection vulnerability in Ray-Project Ray, a distributed-computing framework widely used for AI/ML orchestration and distributed workloads. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-17 with a remediation due date of 2026-08-20, signalling confirmed exploitation in the wild.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-62593 |
| Type | Code injection |
| Product | Ray-Project Ray (distributed computing / AI/ML framework) |
| KEV status | Added to KEV 2026-08-17 (BOD 26-04) |
| Due date | 2026-08-20 |
| Exploitation status | Exploited in the wild |
Context
CISA added the vulnerability to its KEV catalogue on 17 August 2026 with a three-day remediation deadline, confirming active exploitation. Ray is a popular open-source framework for scaling AI/ML and distributed workloads, making internet-facing deployments a high-priority patch target. The addition continues a week of KEV activity (Cisco ASA/FTD, Windows WinSock, Metabase) and reinforces the two-week BOD 26-04 federal patch directive.
Related Pages
- Cisa Adds Ray Project Ray Code Injection Flaw To Known Exploited Vulnerabilities โ CISA KEV addition incident
Sources: raw/digests/Cyber-Digest-2026-08-18