U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
ID: 9491236a-88ff-5698-8c8c-6001cd0cb2ec
STIX ID: report--9491236a-88ff-5698-8c8c-6001cd0cb2ec
Feed Name: Security Affairs
Threat Score
CISA added CVE-2025-62593 — a critical remote code execution flaw in the Ray AI Compute Engine — to its Known Exploited Vulnerabilities catalog; the issue (CVSS 9.4) stems from insufficient User-Agent validation that can be abused with DNS rebinding to execute arbitrary code on developer machines, and Ray 2.52.0 patches the vulnerability while federal agencies were ordered to remediate by August 20, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
