# CISA adds Ray-Project code injection to KEV

Published: 2026-08-17 · Severity: high
Canonical: https://vorant.io/reports/9905a3ac-f8cb-5ad9-853d-04074afa5fab/cisa-adds-ray-project-code-injection-to-kev

> CISA added CVE-2025-62593, a code injection flaw in Ray-Project Ray, to its Known Exploited Vulnerabilities catalog due to active exploitation.

CISA has added CVE-2025-62593, a code injection vulnerability affecting Ray-Project's Ray framework, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The advisory itself provides no technical details on the exploitation vector, threat actors involved, or targeted sectors, only confirming that active exploitation has been observed.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting full post-exploitation control, and to check for prior compromise before patching. While the directive applies only to federal agencies, CISA recommends all organizations using Ray adopt risk-based patching and remediate this vulnerability promptly given confirmed exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-62593 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9905a3ac-f8cb-5ad9-853d-04074afa5fab/cisa-adds-ray-project-code-injection-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
