criticalZero-Day

CISA KEV Addition: Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593)

First seen Aug 18, 2026 · Updated Aug 18, 2026

CISAKEVcode-injectionrayagent-relevantML-infrastructurefederal-mandate

CISA added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis due to its potential to grant full control of affected assets.

Technical Analysis

CVE-2025-62593 is a code injection flaw in Ray, a widely used open-source distributed computing framework commonly deployed for scaling machine learning training, inference, and hyperparameter tuning workloads. Active exploitation suggests attackers can inject and execute arbitrary code on Ray clusters, potentially achieving full compromise of the underlying compute nodes. Given Ray's central role in orchestrating distributed ML/LLM training and serving pipelines, exploitation could allow attackers to manipulate model training, exfiltrate proprietary model weights or training data, or pivot laterally into connected data stores and API credential stores. Because Ray clusters frequently host or interface with AI agent orchestration, LLM fine-tuning jobs, and RAG data pipelines, compromise of these clusters presents a direct and significant risk to organizations running agentic AI infrastructure, including theft of API keys, model tampering, and supply-chain poisoning of downstream agent deployments.

Affected Systems

Ray-Project Ray distributed computing framework (specific vulnerable versions not disclosed in source; organizations should consult the official CVE record and Ray security advisories for exact version ranges). Publicly exposed Ray dashboard/API endpoints and clusters used for ML/LLM training or agent orchestration are of particular concern.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this alert; refer to CISA KEV Catalog entry for CVE-2025-62593 and Ray-Project security advisories for updates.

Remediation Steps

  1. 1

    Patch Ray Deployments

    Upgrade to the patched version of Ray as specified in the official CVE-2025-62593 advisory and vendor guidance.

  2. 2

    Restrict Public Exposure

    Ensure Ray dashboards, APIs, and cluster management interfaces are not exposed to the public internet; enforce network segmentation and authentication.

  3. 3

    Follow BOD 26-04 Guidance

    FCEB agencies must remediate per Binding Operational Directive 26-04 timelines; all organizations should treat this as high priority given evidence of active exploitation.

  4. 4

    Audit for Prior Compromise

    Review logs and system integrity on any internet-facing Ray clusters for indicators of exploitation predating patch deployment, consistent with BOD 26-04 compromise-assessment requirements.

  5. 5

    Rotate Exposed Credentials

    If Ray clusters interact with AI agent pipelines, LLM APIs, or cloud credentials, rotate any keys or secrets accessible from compromised nodes.

CVE / Advisory IDs

CVE-2025-62593

Industries Most Exposed

TechnologyGovernmentResearch/AcademiaAI/ML Infrastructure ProvidersCloud Services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.