VORANT. Threat Intelligence Sign in Get the full feed

CISA adds Ray-Project code injection to KEV

high vulnerability

CISA added CVE-2025-62593, a code injection flaw in Ray-Project Ray, to its Known Exploited Vulnerabilities catalog due to active exploitation.

CISA has added CVE-2025-62593, a code injection vulnerability affecting Ray-Project's Ray framework, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The advisory itself provides no technical details on the exploitation vector, threat actors involved, or targeted sectors, only confirming that active exploitation has been observed.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting full post-exploitation control, and to check for prior compromise before patching. While the directive applies only to federal agencies, CISA recommends all organizations using Ray adopt risk-based patching and remediate this vulnerability promptly given confirmed exploitation.

Mentioned in this report

Vulnerabilities CVE-2025-62593KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free