VYPR
kevPublished Aug 17, 2026· 1 source

CISA Adds Ray-Project Vulnerability to Known Exploited Vulnerabilities Catalog

CISA has added CVE-2025-62593, a code injection vulnerability in Ray-Project, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of CVE-2025-62593 to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that the vulnerability, which affects the Ray-Project, has been observed under active exploitation in the wild, posing a significant threat to organizations.

The vulnerability, identified as a code injection flaw within the Ray-Project, allows malicious actors to execute arbitrary code on affected systems. Such vulnerabilities are frequently leveraged by cybercriminals as an initial access vector to compromise networks, deploy ransomware, or steal sensitive data. The inclusion in the KEV catalog underscores the urgency for organizations to address this specific security risk.

Federal Civilian Executive Branch (FCEB) agencies are mandated by Binding Operational Directive (BOD) 26-04 to prioritize the remediation of vulnerabilities listed in the KEV Catalog, particularly on publicly exposed assets. This directive emphasizes a risk-based approach to vulnerability management, requiring agencies to focus on flaws that grant complete control of an asset post-exploitation. The addition of CVE-2025-62593 to the KEV list means FCEB agencies must now prioritize its patching on internet-facing systems.

While BOD 26-04 specifically targets federal agencies, CISA strongly encourages all organizations, including those in the private sector, to adopt similar risk-based vulnerability management practices. Prioritizing the patching of known exploited vulnerabilities is a critical step in bolstering an organization's overall security posture and reducing its attack surface.

CISA continuously monitors the threat landscape for vulnerabilities that meet the criteria for inclusion in the KEV Catalog. These criteria typically include the existence of a CVE ID, documented evidence of active exploitation, and clear guidance on how to mitigate the vulnerability. The agency also provides a nomination form for the public to submit potential candidates for inclusion.

The Ray-Project is an open-source framework designed to scale AI and Python applications. Its widespread use in machine learning and distributed computing environments means that a vulnerability like CVE-2025-62593 could have a broad impact across various industries and research sectors.

Organizations that utilize the Ray-Project should consult the official Ray documentation for specific guidance on identifying affected versions and applying necessary patches or workarounds. Proactive security measures, including regular vulnerability scanning and prompt patching, are essential to defend against threats exploiting known vulnerabilities.

Synthesized by Vypr AI