CISA Mandates Federal Agencies Patch Critical Ray AI Flaw by August 20
CISA added CVE-2025-62593, a code-injection vulnerability in the Ray AI compute engine, to its Known Exploited Vulnerabilities catalog on August 17, 2026, citing active exploitation and assigning a CVSS 4.0 score of 9.4. Federal Civilian Executive Branch agencies have until August 20 to remediate, with the fix requiring an upgrade to Ray version 2.52.0 or higher. The attack targets developers via DNS-rebinding through Firefox or Safari browsers, enabling remote code execution against Ray instances running on private corporate networks.